在 hawtio-operator 中发现一个缺陷:该 Operator 的 ClusterRole 授予了在所有命名空间中对 Secrets 执行 [create, get, list, update, watch] 操作的权限。虽然该 Operator 使用基于 controller-runtime 的 label-selector 缓存作为内存优化手段,但其 ServiceAccount 令牌已授权对集群中所有 Secrets 的读取访问权限。此外,该 Operator 还会通过直接调用 API 来绕过缓存机
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Red Hat | Red Hat build of Apache Camel - HawtIO 4 | any |
affected |
any |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat build of Apache Camel - HawtIO 4 | - |
cpe:/a:redhat:apache_camel_hawtio:4
|
|
| Red Hat | Red Hat build of Apache Camel - HawtIO 4 | - |
cpe:/a:redhat:apache_camel_hawtio:4
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-78234 | 9.9 CRITICAL | Hawtio-operator: hawtio-operator: service-ca signing oracle allows arbitrary-cn certificat |
| CVE-2026-80219 | 8.7 HIGH | Hawtio-operator: hawtio-operator: oauthclient created with grantmethod auto and no secret |
| CVE-2026-74860 | 8.5 HIGH | Libxml2: double-free/uaf in libxml2 python bindings |
| CVE-2026-76561 | 7.2 HIGH | Pki-core: dogtag/pki: certprofile-import allows code execution via unsanitized profile con |
| CVE-2026-74859 | 6.8 MEDIUM | Gnome-tweaks: path traversal in theme installer |
| CVE-2026-18090 | 6.1 MEDIUM | Gdk-pixbuf: gdk-pixbuf: heap out-of-bounds read in uncompress() via crafted icns rle block |
| CVE-2026-86564 | 3.3 LOW | Dpdk: dpdk: missing length validation before reading command_data in virtio-net control qu |
No comments yet