在 search-v2-operator 中发现了一个漏洞。该漏洞允许具有特权的用户(具体为自定义资源(CR)编辑器)在未经验证的情况下操纵搜索 CR 字段,例如 imageOverride、参数和环境变量。通过利用此漏洞,攻击者可以将任意秘密挂载到搜索容器的环境中,或用攻击者控制的镜像替换容器镜像。这会导致权限提升,并可能由于 ServiceAccount 具有广泛的 impersonation(模拟)权限,从而导致整个集群被完全入侵。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Red Hat | Red Hat Advanced Cluster Management for Kubernetes 2 | any |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat Advanced Cluster Management for Kubernetes 2.13 | 1787682112 ~ * |
cpe:/a:redhat:acm:2.13::el9
|
|
| Red Hat | Red Hat Advanced Cluster Management for Kubernetes 2.15 | 1787681674 ~ * |
cpe:/a:redhat:acm:2.15::el9
|
|
| Red Hat | Red Hat Advanced Cluster Management for Kubernetes 2.17 | 1787681651 ~ * |
cpe:/a:redhat:acm:2.17::el9
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-70496 | 9.9 CRITICAL | Search-v2-operator: search-v2-operator: operator clusterrole is cluster-admin equivalent v |
| CVE-2026-66794 | 9.3 CRITICAL | Cluster-proxy-addon: cluster-proxy-addon: unauthenticated ssrf to arbitrary managed-cluste |
| CVE-2026-76139 | 8.0 HIGH | Acm-operator-bundle: acm-operator-bundle: bundle build execs unpinned stolostron/release@m |
| CVE-2026-75569 | 7.7 HIGH | Mce-operator-bundle: mce-operator-bundle: bundle-generation business logic fetched from mu |
| CVE-2026-76235 | 7.5 HIGH | Cockpit-ws: cockpit: cockpit-ws: unauthenticated remote memory leak via cockpitlang cookie |
| CVE-2026-76827 | 6.8 MEDIUM | Search-indexer: search-indexer: update/delete operations not scoped to caller's cluster (c |
| CVE-2026-18874 | 6.2 MEDIUM | Volsync-addon-controller: volsync-addon-controller: annotation values rendered into yaml v |
| CVE-2026-75900 | 6.1 MEDIUM | Swtpm: swtpm: out-of-bounds read in swtpm_nvram_checkheader due to sizeof(pointer) vs size |
| CVE-2026-76166 | 4.3 MEDIUM | Modcluster-core: mod_cluster advertise listener: unauthenticated dos via crafted multicast |
No comments yet