在 openshift/console 中发现了一个漏洞。未经验证的远程攻击者可以利用 CatalogdHandler 中的配置错误,该组件缺乏适当的身份验证,并转发 cookie。这使得攻击者能够向集群内的 catalogd 服务发送请求,导致内部 operator-catalog 索引泄露,并为进入 openshift-catalogd 命名空间提供了中继途径。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat OpenShift Container Platform 4 | - |
cpe:/a:redhat:openshift:4
|
|
| Red Hat | Red Hat OpenShift Container Platform 4 | - |
cpe:/a:redhat:openshift:4
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-84474 | 9.9 CRITICAL | Automation-controller: automation-controller-container: automation-controller: view_jobtem |
| CVE-2026-84502 | 9.9 CRITICAL | Automation-controller: automation-controller-container: automation-controller: project scm |
| CVE-2026-84719 | 9.9 CRITICAL | Automation-controller: automation-controller: workflowjobtemplate /copy/ deep-copy sanitiz |
| CVE-2026-75884 | 9.1 CRITICAL | Awx: awx: privilege escalation to openshift namespace via pod_spec_override injection in c |
| CVE-2026-96275 | 8.8 HIGH | Flatpak: flatpak: arbitrary write access as root via extra-data extraction |
| CVE-2026-84691 | 8.7 HIGH | Automation-controller: automation-controller-container: automation-controller: format stri |
| CVE-2026-84683 | 8.7 HIGH | Automation-controller: automation-controller-container: automation-controller: stored cros |
| CVE-2026-76648 | 8.5 HIGH | Automation-controller: automation-controller-container: aap controller: copyapiview.post() |
| CVE-2026-84486 | 8.2 HIGH | Automation-controller: automation-controller-container: automation-controller: unauthentic |
| CVE-2026-96512 | 7.8 HIGH | Sudo: sudo: tz environment variable allows bypass of notbefore/notafter time-based authori |
| CVE-2026-96889 | 7.8 HIGH | Librsvg: use-after-free when xml includes have duplicated entities |
| CVE-2026-84499 | 7.7 HIGH | Automation-controller: automation-controller-container: automation-controller: write-only |
| CVE-2026-84706 | 7.6 HIGH | Automation-controller: automation-controller-container: automation-controller: credential |
| CVE-2026-96541 | 7.5 HIGH | Gnome-remote-desktop: gnome-remote-desktop: unauthenticated rdp sockets lack a handshake d |
| CVE-2026-75887 | 7.5 HIGH | Openshift/console: openshift/console: unauthenticated path traversal in i18n locale handle |
| CVE-2026-88830 | 7.5 HIGH | Busybox: busybox: tls montgomery reduction allocates bytes instead of digits, causing a pr |
| CVE-2026-88832 | 7.3 HIGH | Busybox: busybox: romfs volume id parsing performs unbounded memcpy into fixed-size label |
| CVE-2026-85475 | 7.2 HIGH | Automation-controller: automation-controller-container: automation-controller: rsyslog con |
| CVE-2026-84714 | 7.1 HIGH | Automation-controller: automation-controller: incomplete sanitize_jinja() regex allows jin |
| CVE-2026-96445 | 6.8 MEDIUM | Keycloak-services: keycloak-services: conditional otp skip-header policy evaluated against |
Showing top 20 of 46 CVEs. View all on vendor page → →
No comments yet