Nuclio 是一个用于实时事件和数据处理的“无服务器”(Serverless)框架。在 1.16.0 版本之前,Nuclio Dashboard 的项目管理 API 存在一个漏洞:任何已认证的用户(即使不是目标项目的成员)都可以绕过 OPA 授权检查,通过写操作路径(PUT /api/projects/{id}、DELETE /api/projects)修改或删除任意项目及其关联资源(如函数、API 网关等)。该问题已在 1.16.0 版本中修复。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-79756 | 8.7 HIGH | Nuclio: Unauthenticated OS command injection via namespace header in list-all resource pat |
| CVE-2026-52833 | 8.0 HIGH | Nuclio: Unsanitized runtimeAttributes.repositories injected into Groovy build.gradle leads |
| CVE-2026-52831 | 8.0 HIGH | Nuclio: Unsanitized cron trigger event headers/body injected into CronJob shell command le |
| CVE-2026-79755 | 8.0 HIGH | Nuclio: Unauthenticated OS command injection via function namespace in docker ps --filter |
| CVE-2026-79754 | 7.1 HIGH | Nuclio: Kaniko build tempDir command injection |
| CVE-2026-52832 | 4.9 MEDIUM | Nuclio: Unauthenticated path traversal in spec.handler allows arbitrary file write in Dash |
No comments yet