OpenShift Windows Machine Config Operator是OpenShift公司开源的一个Windows机器配置操作员软件。 OpenShift Windows Machine Config Operator存在加密问题漏洞,该漏洞源于建立SSH连接时未验证远程服务器主机密钥,可能导致相邻网络攻击者拦截或重定向SSH会话并捕获WICD和kubelet引导凭据,从而危及集群中Windows节点身份。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Red Hat | Red Hat OpenShift Container Platform 4 | any |
affected |
any |
affected | ||
| Red Hat | Red Hat OpenShift for Windows Containers 10.21 | 1787065708< * |
unaffected |
| Red Hat | Red Hat OpenShift for Windows Containers 10.22 | 1783692800< * |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat OpenShift for Windows Containers 10.21 | 1787065708 ~ * |
cpe:/a:redhat:windows_machine_config:10.21::el9
|
|
| Red Hat | Red Hat OpenShift for Windows Containers 10.22 | 1783692800 ~ * |
cpe:/a:redhat:windows_machine_config:10.22::el9
|
|
| Red Hat | Red Hat OpenShift Container Platform 4 | - |
cpe:/a:redhat:openshift:4
|
|
| Red Hat | Red Hat OpenShift Container Platform 4 | - |
cpe:/a:redhat:openshift:4
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-54099 | 8.8 HIGH | Windows-machine-config-operator: windows-machine-config-operator: wicd csr extra-organizat |
| CVE-2026-12725 | 5.9 MEDIUM | Dnsmasq: dnsmasq: heap buffer overflow in log_query() when logging unsupported ds/dnskey r |
| CVE-2026-12549 | 4.8 MEDIUM | Libsoup: incomplete fix for cve-2026-2443: range suffix overflow in libsoup soupserver |
No comments yet