漏洞描述: 在 hawtio-operator 中发现一个缺陷。当配置了自定义的 Route TLS 密钥(secret),且操作符(operator)运行在调试日志级别 1 或更高时,整个 Route 对象——包括以 PEM 格式存储的 TLS 私钥——会被序列化为 JSON 并写入操作符的标准输出。由于操作符的日志通常会被转发到集中式日志系统,任何拥有 openshift-operators 命名空间中 Pod 日志访问权限的用户都可能读取到这些日志。而调试级别 1 是一个较低的阈值,在故障排查时常常会被启用。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat build of Apache Camel - HawtIO 4 | - |
cpe:/a:redhat:apache_camel_hawtio:4
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-75092 | 7.3 HIGH | Leapp-repository: leapp-upgrade-el9toel10: leapp-upgrade-el9toel10: scan_mysql runs mysqld |
| CVE-2026-81303 | 6.3 MEDIUM | Hawtio-operator: hawtio-operator: routes/custom-host confused-deputy via spec.routehostnam |
| CVE-2026-91786 | 6.1 MEDIUM | Gnome-shell: gnome-shell: out-of-bounds read in remote search icon rendering due to unvali |
No comments yet