Nuclio 是一个用于实时事件和数据处理的“Serverless”框架。在版本 1.6.19 至 1.17.2 之前的版本中,Nuclio 仪表盘的构建流水线在将 字段用于构建 shell 命令前,未对其进行清洗(sanitization)。当启用 Kaniko 容器构建器时,拥有函数创建权限的用户可以向该字段注入 shell 元字符,从而在运行于 Kubernetes 服务账户(该账户在其命名空间内对 Secrets、Pods、Jobs 和 Deployments 具有通配符访问权限)的 Dashboard 容
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-79756 | 8.7 HIGH | Nuclio: Unauthenticated OS command injection via namespace header in list-all resource pat |
| CVE-2026-45730 | 8.3 HIGH | Nuclio: Missing authorization on project write paths allows any authenticated user to modi |
| CVE-2026-52833 | 8.0 HIGH | Nuclio: Unsanitized runtimeAttributes.repositories injected into Groovy build.gradle leads |
| CVE-2026-52831 | 8.0 HIGH | Nuclio: Unsanitized cron trigger event headers/body injected into CronJob shell command le |
| CVE-2026-79755 | 8.0 HIGH | Nuclio: Unauthenticated OS command injection via function namespace in docker ps --filter |
| CVE-2026-52832 | 4.9 MEDIUM | Nuclio: Unauthenticated path traversal in spec.handler allows arbitrary file write in Dash |
No comments yet