Red Hat OpenShift AI是美国红帽(Red Hat)公司的一款面向AI的生命周期管理平台。 Red Hat OpenShift AI存在路径遍历漏洞,该漏洞源于/read-document端点访问控制不当,可能导致未经验证的远程攻击者读取任意文件。
| 厂商 | 产品 | 版本范围 | 状态 |
|---|---|---|---|
| Red Hat | Red Hat OpenShift AI (RHOAI) | 全部 |
affected |
全部 |
unaffected | ||
全部 |
unaffected | ||
全部 |
unaffected | ||
全部 |
unaffected | ||
全部 |
unaffected | ||
全部 |
unaffected | ||
全部 |
unaffected | ||
| … +6 条更多 | |||
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
| 厂商 | 产品 | 影响版本 | CPE | 订阅 |
|---|---|---|---|---|
| Red Hat | Red Hat OpenShift AI (RHOAI) | - |
cpe:/a:redhat:openshift_ai
|
|
| Red Hat | Red Hat OpenShift AI (RHOAI) | - |
cpe:/a:redhat:openshift_ai
|
|
| Red Hat | Red Hat OpenShift AI (RHOAI) | - |
cpe:/a:redhat:openshift_ai
|
|
| Red Hat | Red Hat OpenShift AI (RHOAI) | - |
cpe:/a:redhat:openshift_ai
|
|
| Red Hat | Red Hat OpenShift AI (RHOAI) | - |
cpe:/a:redhat:openshift_ai
|
|
| Red Hat | Red Hat OpenShift AI (RHOAI) | - |
cpe:/a:redhat:openshift_ai
|
|
| Red Hat | Red Hat OpenShift AI (RHOAI) | - |
cpe:/a:redhat:openshift_ai
|
|
| Red Hat | Red Hat OpenShift AI (RHOAI) | - |
cpe:/a:redhat:openshift_ai
|
|
| Red Hat | Red Hat OpenShift AI (RHOAI) | - |
cpe:/a:redhat:openshift_ai
|
|
| Red Hat | Red Hat OpenShift AI (RHOAI) | - |
cpe:/a:redhat:openshift_ai
|
|
| Red Hat | Red Hat OpenShift AI (RHOAI) | - |
cpe:/a:redhat:openshift_ai
|
|
| Red Hat | Red Hat OpenShift AI (RHOAI) | - |
cpe:/a:redhat:openshift_ai
|
|
| Red Hat | Red Hat OpenShift AI (RHOAI) | - |
cpe:/a:redhat:openshift_ai
|
|
| Red Hat | Red Hat OpenShift AI (RHOAI) | - |
cpe:/a:redhat:openshift_ai
|
|
| # | POC 描述 | 源链接 | 神龙链接 |
|---|---|---|---|
| 1 | Feast (the open-source Feature Store) Feature Server through 0.58.0 exposes an unauthenticated POST /read-document endpoint that reads an arbitrary, caller-supplied file path with no authentication and no path validation. The read_document_endpoint handler passes the JSON `file_path` field straight to os.path.exists()/open() and returns the file contents in the JSON `content` field, so a remote, unauthenticated attacker can read any file readable by the server process (e.g. /etc/passwd, feature_store.yaml, cloud credentials). Unlike the store-mutating routes it carries no inject_user_details/permission dependency. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-23536.yaml | POC详情 |
未找到公开 POC。
登录以生成 AI POC暂无评论