在 Maestro 中发现了一个安全漏洞。其 REST API 的写入端点注册时未配置适当的身份验证中间件。这允许远程攻击者执行未经授权的写入操作,例如创建、修改或删除消费者(consumers)和资源包(resource bundles)。此类问题可能导致数据完整性受损,或引发拒绝服务(DoS)攻击。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Red Hat | Multicluster Engine for Kubernetes | any |
affected |
any |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Multicluster Engine for Kubernetes | - |
cpe:/a:redhat:multicluster_engine
|
|
| Red Hat | Multicluster Engine for Kubernetes | - |
cpe:/a:redhat:multicluster_engine
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-101919 | 8.8 HIGH | Hypershift: hypershift: unsanitized kubeconfig passthrough from tenant namespace to contro |
| CVE-2026-105306 | 6.5 MEDIUM | Keycloak-services: keycloak-services: token introspection audience bypass via dynamic clie |
| CVE-2026-71298 | 6.4 MEDIUM | Maestro: sql identifier injection via properties.* search filter and orderby field |
| CVE-2026-105302 | 5.7 MEDIUM | Keycloak-services: keycloak-services: user session note mapper exposes upstream idp access |
| CVE-2026-104030 | 5.5 MEDIUM | Sssd: sssd: denial of service via out-of-bounds read during passkey parsing |
| CVE-2026-71297 | 5.4 MEDIUM | Maestro: maestro: grpc broker has no auth interceptor and client mtls is optional |
| CVE-2026-102295 | 5.4 MEDIUM | Quay: quay: dom-based cross-site scripting via oauth local callback format=json parameter |
| CVE-2026-102576 | 4.2 MEDIUM | Quay: quay: dom-based cross-site scripting via unvalidated redirect_url on signin page |
| CVE-2026-105301 | 4.0 MEDIUM | Keycloak-services: keycloak-services: blind ssrf via x.509 authenticator fetching attacker |
| CVE-2026-104029 | 3.3 LOW | Sssd: sssd: denial of service via out-of-bounds read in autofs responder |
| CVE-2026-105326 | 2.5 LOW | Cups: cups: argument injection in mailto notifier via notify-recipient-uri |
No comments yet