描述 拥有 setuid-root 权限的 可执行文件会在以有效用户 ID 为 0 的身份运行时,通过遍历文件系统树(FTS)并针对每个条目的完整路径调用 和 ,从而调整 worker 目录的所有者和权限。这两个系统调用在调用时都会重新解析路径,且发生在 FTS 对条目进行分类之后。而被遍历的文件树由不受信任的拓扑(topology)用户拥有并可写。 因此,在 supervisor 节点上运行代码的租户可以在“分类”与“特权操作”之间将中间目录组件替换为符号链接,从而将 root 所有的 或 重定向到主机上的任意文
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Apache Software Foundation | Apache Storm Worker Launcher | 3.0.0 ~ 3.1.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-82434 | 10.0 CRITICAL | Apache Storm Nimbus, Apache Storm Client: Disclosure of the Topology ZooKeeper Credential |
| CVE-2026-78330 | Apache Syncope: Privilege escalation for admin user via JWT authentication | |
| CVE-2026-73579 | Apache Syncope: Non-recursive Any search could skip Realms restrictions | |
| CVE-2026-75015 | Apache Syncope: Nested secrets leak cleartext into audit records readable | |
| CVE-2026-75030 | Apache Syncope: Incomplete authorization checks for Group members deprovisioning | |
| CVE-2026-77051 | Apache Syncope: SQL injection via unsanitized entityKey and opEvent in Audit Events search | |
| CVE-2026-73668 | Apache Syncope: Cross-realm disclosure of confidential ConnId bundles configuration values | |
| CVE-2026-77147 | Apache Syncope: Groovy Sandbox escape for empty CommandArgs | |
| CVE-2026-77181 | Apache Syncope: ClientApp update entitlement not effective | |
| CVE-2026-77883 | Apache Syncope: Information disclosure via one-hop JEXL navigation past the JexlContextBui | |
| CVE-2026-78318 | Apache Syncope: Unauthenticated reflected XSS in Console and Enduser | |
| CVE-2026-73470 | Apache Syncope: Delegating users can grant unowned Roles | |
| CVE-2026-78336 | Apache Syncope: OIDCC4UI provider list discloses client secrets to any authenticated user | |
| CVE-2026-82232 | Apache Syncope: SQL injection via sort parameter in Task search | |
| CVE-2026-86460 | Apache Syncope: Cypher Injection via FIQL Search on Neo4j Persistence | |
| CVE-2026-87779 | Apache Syncope: AES Secret Key disclosure via log output | |
| CVE-2026-87785 | Apache Syncope: JWT subject spoofing | |
| CVE-2026-87802 | Apache Syncope: SRA OAuth2 JWT signature verification bypass | |
| CVE-2026-68570 | Apache Doris: Authorization bypass leading to unauthorized data access | |
| CVE-2026-72524 | Apache Doris: Authorization bypass allowing a low-privilege user to read/write/drop arbitr |
Showing top 20 of 39 CVEs. View all on vendor page → →
No comments yet