在 Eclipse Ankaios 版本 v0.5.1 至 v1.0.1 中,代理端的控制接口(Control Interface)授权器对以通配符开头的多段允许规则(allow rules)进行评估时存在错误。当一个经过身份验证的工作负载(workload)受此类规则限制时,它可以提交 或 ,其中字段掩码(field mask)为空。该请求可能被错误地授权为匹配受限规则,从而允许该工作负载读取完整的集群状态,或在其授权子树之外替换状态。这可能导致其他工作负载或集群配置发生未授权的披露或修改。只有仅由 组成的规则才
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Eclipse Foundation | Eclipse Ankaios | 0.5.1 ~ 1.0.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-19204 | 8.7 HIGH | Jetty 21 未知WebSocket操作码导致堆内存耗尽 |
| CVE-2026-85201 | 6.8 MEDIUM | Eclipse Ankaios 0.1.0-1.0.1 内存分配越界漏洞 |
No comments yet