WildFly Elytron 中发现了一个缺陷。密码哈希和验证过程使用 Unicode NFKC 规范化输入,这可能导致全角字符被压缩(规范化)为对应的 ASCII 字符。远程攻击者可以通过使用仅包含 ASCII 字符的字典,对那些本应包含非 ASCII 字符的账户密码进行猜测,从而更容易破解受影响用户的密码,导致未经授权的访问。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Red Hat | Red Hat build of Apache Camel 4 for Quarkus 3 | any |
affected |
| Red Hat | Red Hat build of Debezium 3 | any |
affected |
| Red Hat | Red Hat Build of Keycloak | any |
affected |
any |
affected | ||
| Red Hat | Red Hat build of Quarkus | any |
affected |
| Red Hat | Red Hat Data Grid 8 | any |
affected |
| Red Hat | Red Hat JBoss Enterprise Application Platform 7 | any |
affected |
any |
affected | ||
any |
affected | ||
| Red Hat | Red Hat JBoss Enterprise Application Platform 8 | any |
affected |
| Red Hat | Red Hat JBoss Enterprise Application Platform Expansion Pack | any |
affected |
| Red Hat | Red Hat Single Sign-On 7 | any |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat build of Apache Camel 4 for Quarkus 3 | - |
cpe:/a:redhat:camel_quarkus:3
|
|
| Red Hat | Red Hat build of Debezium 3 | - |
cpe:/a:redhat:debezium:3
|
|
| Red Hat | Red Hat Build of Keycloak | - |
cpe:/a:redhat:build_keycloak:
|
|
| Red Hat | Red Hat Build of Keycloak | - |
cpe:/a:redhat:build_keycloak:
|
|
| Red Hat | Red Hat build of Quarkus | - |
cpe:/a:redhat:quarkus:3
|
|
| Red Hat | Red Hat Data Grid 8 | - |
cpe:/a:redhat:jboss_data_grid:8
|
|
| Red Hat | Red Hat JBoss Enterprise Application Platform 7 | - |
cpe:/a:redhat:jboss_enterprise_application_platform:7
|
|
| Red Hat | Red Hat JBoss Enterprise Application Platform 7 | - |
cpe:/a:redhat:jboss_enterprise_application_platform:7
|
|
| Red Hat | Red Hat JBoss Enterprise Application Platform 7 | - |
cpe:/a:redhat:jboss_enterprise_application_platform:7
|
|
| Red Hat | Red Hat JBoss Enterprise Application Platform 8 | - |
cpe:/a:redhat:jboss_enterprise_application_platform:8
|
|
| Red Hat | Red Hat JBoss Enterprise Application Platform Expansion Pack | - |
cpe:/a:redhat:jbosseapxp
|
|
| Red Hat | Red Hat Single Sign-On 7 | - |
cpe:/a:redhat:red_hat_single_sign_on:7
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-67567 | 9.9 CRITICAL | Multicloud-operators-subscription: multicloud-operators-subscription: helmrelease chart ap |
| CVE-2026-66788 | 9.9 CRITICAL | Lighthouse: lighthouse: arbitrary local-namespace injection via attacker-controlled labels |
| CVE-2026-66785 | 9.9 CRITICAL | Submariner: submariner: unvalidated endpoint.spec.subnets propagated into wireguard allowe |
| CVE-2026-11861 | 9.6 CRITICAL | Freeipa: idm: ipa: freeipa: obtaining tgs with impersonating cname through trust relations |
| CVE-2026-13097 | 9.1 CRITICAL | Ipa: privilege escalation via krbcanonicalname manipulation due to realm-unaware uniquenes |
| CVE-2026-66787 | 8.7 HIGH | Lighthouse: lighthouse: cross-cluster dns spoofing via unvalidated endpointslice and servi |
| CVE-2026-77176 | 8.1 HIGH | Kata-containers: insufficient validation of createcontainer mount and storage rules in gen |
| CVE-2026-18917 | 7.8 HIGH | Libvirt: integer overflow in nodegetfreepages rpc handler leading to heap buffer overflow |
| CVE-2026-19582 | 7.8 HIGH | Binutils: stack buffer overflow in gnu binutils in rsrc_print_name from an untrusted pe fi |
| CVE-2026-73137 | 7.7 HIGH | Multicloud-operators-subscription: multicloud-operators-subscription: cross-namespace secr |
| CVE-2026-73198 | 7.5 HIGH | Ipa: freeipa: unauthenticated dos in `/ipa/i18n_messages` via unbounded request body read |
| CVE-2026-73197 | 7.5 HIGH | Ipa: freeipa: unauthenticated dos in `/ipa/migration/migration.py` via unbounded request b |
| CVE-2026-73199 | 6.5 MEDIUM | Ipa: freeipa: null pointer dereference in `ipa-enrollment` extended operation (`join_oid`) |
| CVE-2026-77014 | 5.3 MEDIUM | Libsoup: libsoup: integer truncation in sort_ranges() comparator causes silent omission of |
| CVE-2026-73196 | 4.3 MEDIUM | Ipa: freeipa: authenticated dos in `otptoken-add` via unbounded otp key decoding/re-encodi |
No comments yet