hawtio-operator 中存在一个缺陷。该操作符在整个集群范围内拥有 权限,并且直接将 Hawtio 自定义资源中由租户提供的 值写入 Route 规范中,且未进行任何验证或授权检查。通常情况下,命名空间的编辑者无法设置自定义 Route 主机名,但他们可以利用该操作符作为“混淆代理”(confused deputy),从而声明任意外部可路由的主机名。这可能导致子域名接管(subdomain takeover)漏洞,并结合自动授予的 OAuthClient 权限,进一步引发 OAuth 重定向劫持(OAut
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat build of Apache Camel - HawtIO 4 | - |
cpe:/a:redhat:apache_camel_hawtio:4
|
|
| Red Hat | Red Hat build of Apache Camel - HawtIO 4 | - |
cpe:/a:redhat:apache_camel_hawtio:4
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-75092 | 7.3 HIGH | Leapp-repository: leapp-upgrade-el9toel10: leapp-upgrade-el9toel10: scan_mysql runs mysqld |
| CVE-2026-91786 | 6.1 MEDIUM | Gnome-shell: gnome-shell: out-of-bounds read in remote search icon rendering due to unvali |
| CVE-2026-81320 | 5.5 MEDIUM | Hawtio-operator: hawtio-operator: tls private key written to operator log at debug level |
No comments yet