在 maestro 中发现了一个缺陷。远程攻击者可以利用其 REST API 列表端点中 查询参数的 SQL 注入漏洞。该漏洞不需要身份验证,允许只读盲提取数据库中的数据。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Red Hat | Multicluster Engine for Kubernetes | any |
affected |
any |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Multicluster Engine for Kubernetes | - |
cpe:/a:redhat:multicluster_engine
|
|
| Red Hat | Multicluster Engine for Kubernetes | - |
cpe:/a:redhat:multicluster_engine
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-101919 | 8.8 HIGH | Hypershift: hypershift: unsanitized kubeconfig passthrough from tenant namespace to contro |
| CVE-2026-71299 | 6.5 MEDIUM | Maestro: maestro: rest api write endpoints registered without authentication middleware |
| CVE-2026-105306 | 6.5 MEDIUM | Keycloak-services: keycloak-services: token introspection audience bypass via dynamic clie |
| CVE-2026-105302 | 5.7 MEDIUM | Keycloak-services: keycloak-services: user session note mapper exposes upstream idp access |
| CVE-2026-105447 | 5.5 MEDIUM | Quay: quay: global read-only superuser can access build trigger write credentials |
| CVE-2026-104030 | 5.5 MEDIUM | Sssd: sssd: denial of service via out-of-bounds read during passkey parsing |
| CVE-2026-71297 | 5.4 MEDIUM | Maestro: maestro: grpc broker has no auth interceptor and client mtls is optional |
| CVE-2026-102295 | 5.4 MEDIUM | Quay: quay: dom-based cross-site scripting via oauth local callback format=json parameter |
| CVE-2026-102576 | 4.2 MEDIUM | Quay: quay: dom-based cross-site scripting via unvalidated redirect_url on signin page |
| CVE-2026-105301 | 4.0 MEDIUM | Keycloak-services: keycloak-services: blind ssrf via x.509 authenticator fetching attacker |
| CVE-2026-104029 | 3.3 LOW | Sssd: sssd: denial of service via out-of-bounds read in autofs responder |
| CVE-2026-105326 | 2.5 LOW | Cups: cups: argument injection in mailto notifier via notify-recipient-uri |
No comments yet