Red Hat OpenShift GitOps是美国Red Hat公司开源的一个自动化部署服务。 Red Hat OpenShift GitOps存在授权问题漏洞,该漏洞源于ClusterRole reconciler未验证资源所有权,可能导致命名空间范围的Argo CD实例通过名称碰撞触发删除集群范围的Argo CD实例所拥有的ClusterRole,从而导致拒绝服务。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Red Hat | Red Hat OpenShift GitOps | any |
affected |
any |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat OpenShift GitOps | - |
cpe:/a:redhat:openshift_gitops:1
|
|
| Red Hat | Red Hat OpenShift GitOps | - |
cpe:/a:redhat:openshift_gitops:1
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-12382 | 8.2 HIGH | Aap-gateway: missing requestheaderstoremove allows mtls bypass via subject header spoofing |
| CVE-2026-15809 | 7.8 HIGH | Github.com/cri-o/cri-o: fix bypass for cve-2022-4318 — /etc/passwd injection via home env |
| CVE-2026-15779 | 6.1 MEDIUM | Samba-winbind: samba: pam_winbind mkhomedir chowns critical system paths without validatio |
No comments yet