在 NooBaa 的 中的 函数发现了一个操作系统命令注入漏洞。该组件负责管理 OpenShift Data Foundation 中的多云对象网关。此漏洞的发生是因为 参数未经过适当的净化处理,直接传入了 shell 命令中。拥有管理员权限的经过身份验证的攻击者可以提供包含 shell 元字符的特制 ,从而以 NooBaa 进程的权限在宿主系统上执行任意命令。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat Openshift Data Foundation 4 | - |
cpe:/a:redhat:openshift_data_foundation:4
|
|
| Red Hat | Red Hat Openshift Data Foundation 4 | - |
cpe:/a:redhat:openshift_data_foundation:4
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-101292 | 8.2 HIGH | Artemis-core-client: unsafe reflection in apache activemq artemis federation message deser |
| CVE-2026-101333 | 3.7 LOW | Keycloak-services: keycloak-services: unbounded metric series creation via idp tag on brok |
No comments yet