在红帽高级集群管理(Red Hat Advanced Cluster Management for Kubernetes)的 must-gather 组件中发现了一个缺陷。集群的 Proxy 对象以原始形式被导出,绕过了通常会对敏感字段进行脱敏处理的 重命名机制。这导致基本认证(basic-auth)凭据泄露在 must-gather 归档文件中,任何能够访问该归档文件的人都有可能获得这些敏感的认证信息。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Red Hat | Red Hat Advanced Cluster Management for Kubernetes 2 | any |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat Advanced Cluster Management for Kubernetes 2 | - |
cpe:/a:redhat:acm:2
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-66780 | 9.9 CRITICAL | Submariner-operator: submariner-operator: flat broker trust model grants every spoke full |
| CVE-2026-12564 | 9.6 CRITICAL | Automation-controller: automation-controller: kubernetes service account token exfiltratio |
| CVE-2026-18963 | 9.1 CRITICAL | Keycloak-services: keycloak-services: unauthenticated account takeover via reset-credentia |
| CVE-2026-66793 | 8.8 HIGH | Governance-policy-addon-controller: governance-policy-addon-controller: arbitrary containe |
| CVE-2026-75924 | 8.7 HIGH | Managed-serviceaccount: managed-serviceaccount: hub addon-manager clusterrole grants clust |
| CVE-2026-66783 | 8.2 HIGH | Submariner-operator: submariner-operator: arbitrary image override enables privileged code |
| CVE-2026-66782 | 7.8 HIGH | Submariner-operator: submariner-operator: broker api bearer token stored cleartext in cr s |
| CVE-2026-71365 | 7.7 HIGH | Awx: webhook status callback ssrf leaks the git pat |
| CVE-2026-15571 | 7.3 HIGH | Keycloak-services: keycloak-services: predictable account-linking hash enables account tak |
| CVE-2026-66781 | 6.5 MEDIUM | Submariner-operator: submariner-operator: ipsec psk stored cleartext in submariner cr spec |
| CVE-2026-75032 | 6.3 MEDIUM | Bluez: bluez: out-of-bounds read in avrcp parse_media_element and parse_media_folder |
| CVE-2026-73834 | 5.5 MEDIUM | Must-gather: must-gather: embedded secret data in acm wrapper crs collected without redact |
| CVE-2026-19608 | 5.3 MEDIUM | Keycloak-services: keycloak-services: name-only group claims let same-name groups satisfy |
No comments yet