在 pulpcore 中发现了一个路径遍历漏洞。内容上传 API 接受一个名为 的参数,该参数允许具有文件仓库权限的用户指定一个本地文件 URL,以便 Pulp 下载并存储。URL 方案验证检查使用字符串前缀比较,仅拒绝以 开头的 URL,但 Python 的 URL 解析器可以识别不带双斜杠的 方案,导致验证逻辑与传递给文件下载器的内容之间存在不匹配。具有低权限仓库认证权限的用户可以通过提供精心构造的、包含相对路径遍历序列的 URL,读取 Pulp 服务器进程可访问的任何文件。在包含 Pulp Container
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-95521 | 7.8 HIGH | Rpm: rpm: shell command injection via macro expansion of source/spec file basenames when i |
| CVE-2026-95519 | 7.8 HIGH | Rpm: code execution via macro expansion of manifest entries in `rpmgi` (`-q -p` / verify m |
| CVE-2026-97185 | 7.8 HIGH | Gimp: gimp: out-of-bounds write in gimpressionist plugin via crafted preset file |
| CVE-2026-94416 | 6.8 MEDIUM | Aap-gateway: aap-gateway: authorization bypass via workload identity token forgery |
| CVE-2026-97177 | 6.6 MEDIUM | Keycloak-services: keycloak-services: generic user update bypasses denied reset-password p |
| CVE-2026-97311 | 4.3 MEDIUM | Keycloak-services: keycloak-services: admin rest api role-groups endpoint discloses groups |
| CVE-2026-97176 | 4.2 MEDIUM | Keycloak-services: keycloak-services: essential acr requirement silently bypassed via cook |
No comments yet