在 community.general Ansible 集合的 OCAPI 模块(ocapi_command、ocapi_info)中发现了一个缺陷。共享的 OCAPI 请求辅助函数在所有请求中禁用了 TLS 证书验证,且这些模块没有提供参数来重新启用该验证功能,同时它们会向 HTTPS 端点发送 HTTP 基本身份验证(Basic-Auth)凭据。位于 Ansible 控制器与 OCAPI 管理的存储/机箱设备之间网络路径上的攻击者可以出示任意证书,截获会话、捕获凭据,并篡改响应内容。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat Ceph Storage 5 | - |
cpe:/a:redhat:ceph_storage:5
|
|
| Red Hat | Red Hat Ceph Storage 9 | - |
cpe:/a:redhat:ceph_storage:9
|
|
| Red Hat | Red Hat OpenStack Platform 17.1 | - |
cpe:/a:redhat:openstack:17.1
|
|
| Red Hat | Red Hat OpenStack Platform 18.0 | - |
cpe:/a:redhat:openstack:18.0
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-87766 | 8.8 HIGH | Bubblewrap: bubblewrap: symlink traversal via /oldroot allows writing files outside sandbo |
| CVE-2026-18147 | 8.1 HIGH | Freeipa: ipa: freeipa/idm: cross-site scripting vulnerability allows arbitrary code execut |
| CVE-2026-87874 | 8.1 HIGH | Community.general: community.general: memcached cache plugin deserializes untrusted pickle |
| CVE-2026-87853 | 7.5 HIGH | Sssd: sssd: idp authentication prefix comparison allows cross-user impersonation |
| CVE-2026-19729 | 4.9 MEDIUM | Keycloak-services: keycloak-services: incomplete fix for arbitrary filesystem path probing |
| CVE-2026-87875 | 4.3 MEDIUM | Cups: openprinting cups: heap out-of-bounds read in cupsutf32toutf8() via missing source-l |
| CVE-2026-87876 | 3.0 LOW | Cups: openprinting cups: remaining case-insensitive username matching in scheduler side pa |
No comments yet