Linuxfabrik Linuxfabrik Monitoring Plugins是Linuxfabrik组织开源的一系列监控插件软件。 Linuxfabrik monitoring-plugins 6.0.0及之前版本存在安全漏洞,该漏洞源于redfish-*插件构建请求URL时未验证输入,允许恶意或受损的BMC重定向经过身份验证的Redfish请求,导致泄露X-Auth-Token或HTTP Basic凭据。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linuxfabrik | monitoring-plugins | <= 6.0.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Linuxfabrik | monitoring-plugins | <= 6.0.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-67435 | 6.0 MEDIUM | linuxfabrik-lib: fetch() forwards credential headers across a cross-origin redirect |
| CVE-2026-67433 | 5.8 MEDIUM | Linuxfabrik monitoring-plugins: Symlink following in logfile legacy database migration |
No comments yet