这段漏洞描述涉及 Omni(一个用于在裸金属、虚拟机或云环境中管理 Kubernetes 的工具)。以下是该段落的中文翻译: Omni 可用于管理运行在裸金属、虚拟机或云环境中的 Kubernetes。在 1.6.6 和 1.7.3 版本之前, 文件中的 函数将调用者可控的 字段直接传递给 ,且未对其进行版本格式校验。 经过认证的 Operator 用户可以在 字段中注入路径遍历段(如 ),而 会将这些段规范化为配置好的 image-factory 主机上的非预期路径。随后,Omni 会向这些路径发起 HTTP G
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| siderolabs | omni | < 1.6.6 |
affected |
>= 1.7.0, < 1.7.3 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| siderolabs | omni | < 1.6.6 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-45726 | 7.6 HIGH | Omni: Reader-level users can retrieve imported cluster CA keys via ResourceService |
| CVE-2026-45720 | 7.0 HIGH | Omni: TOCTOU race condition allows multiple concurrent uses of a single-use SAML session t |
No comments yet