Renovate 是一个自动化的依赖更新工具。在 44.14.4 之前的版本中(以及 Mend Renovate CE/EE 镜像 15.4.0 之前、mend-renovate-enterprise-edition Helm Chart 10.4.0 之前),针对用于双向 TLS(Mutual TLS)的 TLS 私钥的日志脱敏处理并不完整。虽然 字段本身的值会被掩盖(redacted),但如果该私钥值出现在其他位置——例如在其他配置项中,或出现在日志中并非 键下的消息里——那么该私钥值就不会被掩盖,导致完整的私
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| renovatebot | renovate | 0 ~ 44.14.44 | - |
|
| renovatebot | renovate | 0 ~ 44.14.44 | - |
|
| renovatebot | renovate | 0 ~ 44.14.44 | - |
|
| renovatebot | renovate | 0 ~ 44.14.44 | - |
|
| renovatebot | renovate | 0 ~ 15.4.0 | - |
|
| renovatebot | renovate | 0 ~ 15.4.0 | - |
|
| renovatebot | renovate | 0 ~ 15.4.0 | - |
|
| renovatebot | renovate | 0 ~ 15.4.0 | - |
|
| renovatebot | renovate | 0 ~ 15.4.0 | - |
|
| renovatebot | renovate | 0 ~ 15.4.0 | - |
|
| renovatebot | renovate | 0 ~ 15.4.0 | - |
|
| renovatebot | renovate | 0 ~ 15.4.0 | - |
|
| renovatebot | renovate | 0 ~ 15.4.0 | - |
|
| renovatebot | renovate | 0 ~ 15.4.0 | - |
|
| renovatebot | renovate | 0 ~ 15.4.0 | - |
|
| renovatebot | renovate | 0 ~ 10.4.0 | - |
|
| renovatebot | renovate | 0 ~ 10.4.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-88882 | 8.6 HIGH | Renovate before 44.11.2 Credential Exfiltration via Link Header |
| CVE-2026-88880 | 8.6 HIGH | Renovate before 44.11.3 Credential Exfiltration via Link Header |
| CVE-2026-88881 | 8.6 HIGH | Renovate before 44.11.3 Credential Exfiltration via Link Header |
| CVE-2026-88887 | 8.6 HIGH | Renovate before 44.11.2 Credential Exfiltration via Link Header |
| CVE-2026-88886 | 7.8 HIGH | Renovate before 44.14.7 Command Injection via gradle-wrapper |
| CVE-2026-88889 | 7.8 HIGH | Renovate before 44.14.7 Command Injection via distributionType |
| CVE-2026-88885 | 7.0 HIGH | Renovate before 44.14.7 Command Injection via depName |
| CVE-2026-88888 | 7.0 HIGH | Renovate before 44.14.7 Command Injection via Mix organization |
| CVE-2026-88884 | 5.8 MEDIUM | Renovate before 44.3.1 Authentication Bypass via Digest Updates |
No comments yet