在 openshift/oauth-server 中发现了一个缺陷。OAuth 登录和错误页面端点将未经验证的 请求头传递给 ,且未进行输入校验。 针对 CVE-2022-32149 缓解措施存在一个绕过方式:上游的防护代码仅统计“-”字符的数量,但内部用于扫描 BCP 47 语言的逻辑在防护检查之后会将下划线“_”别名替换为连字符“-”。 因此,未认证的恶意攻击者可以发送一个使用下划线“_”作为分隔符的定制 请求头,从而触发二次方时间复杂度的解析过程,导致大量 CPU 资源被占用,进而使集群中的所有用户无法完成身
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat OpenShift Container Platform 4 | - |
cpe:/a:redhat:openshift:4
|
|
| Red Hat | Red Hat OpenShift Container Platform 4 | - |
cpe:/a:redhat:openshift:4
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-84268 | 8.8 HIGH | Gvfs: sftp: heap-based buffer overflow in read_reply() |
| CVE-2026-84218 | 8.1 HIGH | Org.jolokia/jolokia-core: incomplete jndi denylist in jolokia jsr-160 proxy (bypass of cve |
| CVE-2026-84233 | 7.0 HIGH | Rpm: command execution via macro expansion in `rpmuncompress -x` for crafted `.gem` filena |
| CVE-2026-84269 | 6.5 MEDIUM | Gvfs: afp: heap-based buffer overflow in dsi read path |
| CVE-2026-11873 | 6.5 MEDIUM | Pki-core: dogtag-pki: empty request to dogtag /ca/rest/certrequests causes http 500, java |
| CVE-2026-84232 | 5.4 MEDIUM | Pulpcore: python-pulpcore: stored cross-site scripting via inline rendering of uploaded ht |
| CVE-2026-53682 | 5.3 MEDIUM | Pki-core: dogtag-pki: unauthenticated dogtag ca rest api exposes security domain hosts |
| CVE-2026-84270 | 4.3 MEDIUM | Gvfs: mtp: out-of-bounds read in do_read() |
| CVE-2026-84267 | 4.3 MEDIUM | Gvfs: sftp: uninitialized heap disclosure in read_string() |
No comments yet