在当前 Eclipse aeriOS 的开发版本中(该版本尚未正式发布),身份管理器(IdM)的部署采用了不安全默认配置和安全敏感服务的默认凭证。 Helm Chart 默认通过 Kubernetes NodePort 服务暴露了 Keycloak 服务及其背后的 PostgreSQL 数据库;同样地,Docker Compose 部署方式也将 PostgreSQL 暴露在所有网络接口上。部署中包含了用于 Keycloak 管理员和 PostgreSQL 数据库用户的固定默认凭证,而之前的 Helm Chart 配
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Eclipse Foundation | Eclipse aeriOS | 459fa98e95b1865d01b8d14d6cce5908ba2b18ba< c6efc450baf912385681198b2477c1ba4e93f91a |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Eclipse Foundation | Eclipse aeriOS | 459fa98e95b1865d01b8d14d6cce5908ba2b18ba ~ c6efc450baf912385681198b2477c1ba4e93f91a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-84197 | 9.2 CRITICAL | Ditto Node.js客户端 1.0.0-3.9.0 WebSocket TLS验证缺失 |
| CVE-2026-12611 | 8.7 HIGH | Jetty HTTP/2竞态条件导致服务器无响应 |
| CVE-2026-19203 | 8.3 HIGH | Jetty特制HTTP分块请求致请求走私漏洞 |
| CVE-2026-86590 | 6.3 MEDIUM | Eclipse Che 7.79.0-7.121.0 服务端请求伪造(SSRF) |
No comments yet