Nuclio 是一个用于实时事件和数据处理的“无服务器”(Serverless)框架。在 1.16.5 版本之前,Nuclio 的仪表板(Dashboard)默认情况下(在 NOP 认证模式下)无需身份验证即可访问 POST /api/functions 端点。spec.handler 字段(例如 mymodule:myfunction)由 functionconfig.ParseHandler() 解析,该函数仅以冒号“:”进行分割,且未对模块部分进行路径验证。此问题已在 1.16.5 版本中修复。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-79756 | 8.7 HIGH | Nuclio: Unauthenticated OS command injection via namespace header in list-all resource pat |
| CVE-2026-45730 | 8.3 HIGH | Nuclio: Missing authorization on project write paths allows any authenticated user to modi |
| CVE-2026-52833 | 8.0 HIGH | Nuclio: Unsanitized runtimeAttributes.repositories injected into Groovy build.gradle leads |
| CVE-2026-52831 | 8.0 HIGH | Nuclio: Unsanitized cron trigger event headers/body injected into CronJob shell command le |
| CVE-2026-79755 | 8.0 HIGH | Nuclio: Unauthenticated OS command injection via function namespace in docker ps --filter |
| CVE-2026-79754 | 7.1 HIGH | Nuclio: Kaniko build tempDir command injection |
No comments yet