漏洞描述: ClusterRole 授予了该操作器的服务账号对核心 API 组中“secrets”资源的读取权限,且未设置任何命名空间(namespace)或资源名称(resourceNames)限制。这意味着该服务账号有权访问集群中所有命名空间内的所有密钥(secrets)。 参考链接: https://github.com/openshift/insights-operator/blob/8f15e3157ff09f54ab22801f5b21da35a195cc6d/manifests/03-clusterr
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Red Hat | Red Hat OpenShift Container Platform 4 | any |
affected |
any |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat OpenShift Container Platform 4 | - |
cpe:/a:redhat:openshift:4
|
|
| Red Hat | Red Hat OpenShift Container Platform 4 | - |
cpe:/a:redhat:openshift:4
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-89091 | 8.8 HIGH | Ansible-core: ansible-core: ansible-galaxy collection install symlink path escape allows a |
| CVE-2026-107466 | 6.1 MEDIUM | Flatpak-builder: local file exfiltration via `file |
| CVE-2026-107651 | 5.5 MEDIUM | Eog: eog: arbitrary code execution via heap buffer overflow in png metadata reader |
| CVE-2026-107445 | 5.4 MEDIUM | Rubygem-katello: katello: katello: katello flatpak remote repositories api cross-organizat |
| CVE-2026-107565 | 5.1 MEDIUM | Luksmeta: incomplete gap-boundary and overlap checks in luks1 metadata allocator allow dat |
| CVE-2026-107604 | 4.9 MEDIUM | Keycloak-services: keycloak-services: view-clients role allows retrieval of active client |
| CVE-2026-107444 | 4.3 MEDIUM | Rubygem-katello: katello: katello: katello docker tags repositories api cross-organization |
| CVE-2026-107623 | 4.3 MEDIUM | Keycloak-services: keycloak-services: oidc dcr read-modify-write silently disables offline |
No comments yet