Modcluster mod_cluster是Modcluster社区的一个负载均衡软件。 mod_cluster存在异常处理不当漏洞,该漏洞源于AdvertiseListenerImpl组件未正确处理特制的UDP组播数据报,导致verifyDigest()函数发生空指针解引用,使advertise listener线程永久终止,造成拒绝服务。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Red Hat | Red Hat JBoss Enterprise Application Platform 7 | any |
affected |
| Red Hat | Red Hat JBoss Enterprise Application Platform 8 | any |
affected |
| Red Hat | Red Hat JBoss Enterprise Application Platform Expansion Pack | any |
affected |
| Red Hat | Red Hat JBoss Web Server 5 | any |
unknown |
| Red Hat | Red Hat JBoss Web Server 6 | any |
affected |
| Red Hat | Red Hat JBoss Web Server 7 | any |
affected |
| Red Hat | Red Hat Single Sign-On 7 | any |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat JBoss Enterprise Application Platform 7 | - |
cpe:/a:redhat:jboss_enterprise_application_platform:7
|
|
| Red Hat | Red Hat JBoss Enterprise Application Platform 8 | - |
cpe:/a:redhat:jboss_enterprise_application_platform:8
|
|
| Red Hat | Red Hat JBoss Enterprise Application Platform Expansion Pack | - |
cpe:/a:redhat:jbosseapxp
|
|
| Red Hat | Red Hat JBoss Web Server 5 | - |
cpe:/a:redhat:jboss_enterprise_web_server:5
|
|
| Red Hat | Red Hat JBoss Web Server 6 | - |
cpe:/a:redhat:jboss_enterprise_web_server:6
|
|
| Red Hat | Red Hat JBoss Web Server 7 | - |
cpe:/a:redhat:jboss_enterprise_web_server:7
|
|
| Red Hat | Red Hat Single Sign-On 7 | - |
cpe:/a:redhat:red_hat_single_sign_on:7
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-70496 | 9.9 CRITICAL | Search-v2-operator: search-v2-operator: operator clusterrole is cluster-admin equivalent v |
| CVE-2026-66794 | 9.3 CRITICAL | Cluster-proxy-addon: cluster-proxy-addon: unauthenticated ssrf to arbitrary managed-cluste |
| CVE-2026-71470 | 9.1 CRITICAL | Acm-search-v2-rhel9: search-v2-operator: search cr imageoverride/arguments/envvar flow uns |
| CVE-2026-76139 | 8.0 HIGH | Acm-operator-bundle: acm-operator-bundle: bundle build execs unpinned stolostron/release@m |
| CVE-2026-75569 | 7.7 HIGH | Mce-operator-bundle: all github actions pinned by mutable tag, not commit sha |
| CVE-2026-76235 | 7.5 HIGH | Cockpit-ws: cockpit: cockpit-ws: unauthenticated remote memory leak via cockpitlang cookie |
| CVE-2026-76827 | 6.8 MEDIUM | Search-indexer: search-indexer: update/delete operations not scoped to caller's cluster (c |
| CVE-2026-18874 | 6.2 MEDIUM | Volsync-addon-controller: volsync-addon-controller: annotation values rendered into yaml v |
| CVE-2026-75900 | 6.1 MEDIUM | Swtpm: swtpm: out-of-bounds read in swtpm_nvram_checkheader due to sizeof(pointer) vs size |
No comments yet