hawtio-operator 中发现了一个缺陷。在集群模式下部署 Hawtio 时,该操作员会创建一个集群作用域的 OAuthClient,其授权方式为自动批准(GrantMethod: auto),且不包含客户端密钥(即公共客户端)。重定向 URI 源自操作员创建的 Route,其主机名可通过 Hawtio CR 中的 字段由租户控制。恶意租户可以将任意主机名注册为有效的 OAuth 重定向目标,并且由于授权是自动批准的,任何访问该构造好的授权 URL 的集群用户都将无需同意提示即可被获取其 OpenShift
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Red Hat | Red Hat build of Apache Camel - HawtIO 4 | any |
affected |
any |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat build of Apache Camel - HawtIO 4 | - |
cpe:/a:redhat:apache_camel_hawtio:4
|
|
| Red Hat | Red Hat build of Apache Camel - HawtIO 4 | - |
cpe:/a:redhat:apache_camel_hawtio:4
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-78234 | 9.9 CRITICAL | Hawtio-operator: hawtio-operator: service-ca signing oracle allows arbitrary-cn certificat |
| CVE-2026-74860 | 8.5 HIGH | Libxml2: double-free/uaf in libxml2 python bindings |
| CVE-2026-77968 | 8.2 HIGH | Hawtio-operator: hawtio-operator: cluster-wide secrets read/write granted to operator serv |
| CVE-2026-76561 | 7.2 HIGH | Pki-core: dogtag/pki: certprofile-import allows code execution via unsanitized profile con |
| CVE-2026-74859 | 6.8 MEDIUM | Gnome-tweaks: path traversal in theme installer |
| CVE-2026-18090 | 6.1 MEDIUM | Gdk-pixbuf: gdk-pixbuf: heap out-of-bounds read in uncompress() via crafted icns rle block |
| CVE-2026-86564 | 3.3 LOW | Dpdk: dpdk: missing length validation before reading command_data in virtio-net control qu |
No comments yet