中发现了一个缺陷。远程攻击者可通过利用发布工作流中使用的上游 的漏洞来利用该缺陷,该 Action 被固定到一个可变分支上。这使得攻击者能够注入任意代码,从而导致敏感的注册表凭据泄露或恶意镜像被发布。此外,该工作流还暴露了默认的 GitHub Token,从而加剧了被攻破后的影响严重程度。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat Quay 3 | - |
cpe:/a:redhat:quay:3
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-74909 | 8.1 HIGH | Keycloak-services: keycloak-services: incomplete fix for cve-2026-15573 allows policy enfo |
| CVE-2026-79651 | 7.5 HIGH | Keycloak-services: keycloak-services: unauthenticated dos via unbounded locale caching |
| CVE-2026-18212 | 7.5 HIGH | Keycloak-services: keycloak-services: saml redirect deflate helpers leak native zlib state |
| CVE-2026-42784 | 7.4 HIGH | Sequoia-openpgp: sequoia-openpgp: cryptographic integrity compromise via key flag confusio |
| CVE-2026-17526 | 7.2 HIGH | Keycloak-services: keycloak-services: privilege escalation via impersonation role allows t |
| CVE-2026-92615 | 6.6 MEDIUM | Flightctl: flightctl: package-global go-git https transport mutated per-repo -- cross-tena |
| CVE-2026-92358 | 6.4 MEDIUM | Keycloak-services: keycloak-services: residual cross-browser account-link proof allows sil |
| CVE-2026-92091 | 5.9 MEDIUM | Jwcrypto: jwcrypto: denial of service via o(n^2) duplicate check on unbounded jwk key_ops |
| CVE-2026-19607 | 5.3 MEDIUM | Keycloak-services: keycloak-services: broker-originated username collision causes account |
No comments yet