OpenShift oauth-proxy是OpenShift公司的一款OAuth代理服务器软件。 OpenShift oauth-proxy存在处理逻辑错误漏洞,该漏洞源于代理设置身份验证头时只使用短横线变体键(X-Forwarded-User),但未去除下划线变体键(X_Forwarded_User),导致WSGI和PHP框架将两者标准化为同一变量,允许已认证的低权限用户走私伪造身份,可能覆盖上游应用中的合法身份。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Red Hat | Red Hat OpenShift Container Platform 4.12 | 1786458704< * |
unaffected |
| Red Hat | Red Hat OpenShift Container Platform 4.13 | 1786477436< * |
unaffected |
| Red Hat | Red Hat OpenShift Container Platform 4.14 | 1785549818< * |
unaffected |
| Red Hat | Red Hat OpenShift Container Platform 4.15 | 1787054100< * |
unaffected |
| Red Hat | Red Hat OpenShift Container Platform 4.16 | 1785544039< * |
unaffected |
| Red Hat | Red Hat OpenShift Container Platform 4.17 | 1787543313< * |
unaffected |
| Red Hat | Red Hat OpenShift Container Platform 4.18 | 1785529735< * |
unaffected |
| Red Hat | Red Hat OpenShift Container Platform 4.19 | 1785521728< * |
unaffected |
| Red Hat | Red Hat OpenShift Container Platform 4.20 | 1785833742< * |
unaffected |
| Red Hat | Red Hat OpenShift Container Platform 4.21 | 1785851359< * |
unaffected |
| Red Hat | Red Hat OpenShift Container Platform 4.22 | 1785885351< * |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat OpenShift Container Platform 4.12 | 1786458704 ~ * |
cpe:/a:redhat:openshift:4.12::el9
|
|
| Red Hat | Red Hat OpenShift Container Platform 4.13 | 1786477436 ~ * |
cpe:/a:redhat:openshift:4.13::el9
|
|
| Red Hat | Red Hat OpenShift Container Platform 4.14 | 1785549818 ~ * |
cpe:/a:redhat:openshift:4.14::el9
|
|
| Red Hat | Red Hat OpenShift Container Platform 4.15 | 1787054100 ~ * |
cpe:/a:redhat:openshift:4.15::el9
|
|
| Red Hat | Red Hat OpenShift Container Platform 4.16 | 1785544039 ~ * |
cpe:/a:redhat:openshift:4.16::el9
|
|
| Red Hat | Red Hat OpenShift Container Platform 4.17 | 1787543313 ~ * |
cpe:/a:redhat:openshift:4.17::el9
|
|
| Red Hat | Red Hat OpenShift Container Platform 4.18 | 1785529735 ~ * |
cpe:/a:redhat:openshift:4.18::el9
|
|
| Red Hat | Red Hat OpenShift Container Platform 4.19 | 1785521728 ~ * |
cpe:/a:redhat:openshift:4.19::el9
|
|
| Red Hat | Red Hat OpenShift Container Platform 4.20 | 1785833742 ~ * |
cpe:/a:redhat:openshift:4.20::el9
|
|
| Red Hat | Red Hat OpenShift Container Platform 4.21 | 1785851359 ~ * |
cpe:/a:redhat:openshift:4.21::el9
|
|
| Red Hat | Red Hat OpenShift Container Platform 4.22 | 1785885351 ~ * |
cpe:/a:redhat:openshift:4.22::el9
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-18107 | 7.8 HIGH | Criu: criu: container escape via rseq critical section hijack during checkpoint/restore |
| CVE-2026-16313 | 7.6 HIGH | Sg3_utils: sg3_utils: arbitrary command execution via udev property injection in sg_inq -- |
| CVE-2026-18047 | 6.5 MEDIUM | Dogtag-pki: pki-core: redhat-pki: pki: acme admin enable/disable endpoint authentication b |
| CVE-2026-17072 | 3.3 LOW | Gstreamer1-plugins-good: gst-plugins-good: 4-byte heap over-read in gst_matroska_parse_fla |
No comments yet