在 oc-mirror 中发现了一个漏洞。在执行镜像同步操作期间,内置的本地缓存注册表未进行身份验证或加密,而是绑定到所有网络接口,而非仅限于本地系统访问。相邻网络上的未认证攻击者可以连接到该暴露的服务,从而推送被篡改的容器镜像、删除已缓存的镜像或访问已同步的内容。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Assisted Installer for Red Hat OpenShift Container Platform 2 | - |
cpe:/a:redhat:assisted_installer:2
|
|
| Red Hat | Red Hat OpenShift Container Platform 4 | - |
cpe:/a:redhat:openshift:4
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-96658 | 9.9 CRITICAL | Foreman: safemode bypass leading to rce |
| CVE-2026-96659 | 9.1 CRITICAL | Foreman: excessive permissions for viewer role on preview |
| CVE-2026-86345 | 9.0 CRITICAL | 389-ds-base: 389-ds-base: starttls plaintext-buffer retention allows on-path attacker to f |
| CVE-2026-12405 | 8.8 HIGH | Rubygem-foreman_remote_execution: command injection in job invocations via effective_user |
| CVE-2026-12540 | 8.2 HIGH | Foreman: command injection in foreman-rake errors:fetch_log via request_id parameter |
| CVE-2026-12541 | 8.2 HIGH | Foreman: command injection in foreman-rake database tasks |
| CVE-2026-12544 | 7.7 HIGH | Foreman: ssti and insecure deserialization in foreman-rake configuration |
| CVE-2026-86344 | 7.5 HIGH | 389-ds-base: 389-ds-base: unauthenticated worker-thread-pool exhaustion via completed-oper |
| CVE-2026-12423 | 7.5 HIGH | Foreman: unauthenticated information disclosure via provisioning token validation flaw |
| CVE-2026-12545 | 6.7 MEDIUM | Rubygem-hammer_cli: command injection via insecure editor invocation |
| CVE-2026-56097 | 6.5 MEDIUM | Rubygem-katello: sql injection in registry proxy via labels |
| CVE-2026-103884 | 6.5 MEDIUM | Keycloak-services: keycloak-services: path traversal in x.509 crl distribution point allow |
| CVE-2026-83589 | 6.1 MEDIUM | Oauth-proxy: open redirect via /\ and /\t bypass in post-login redirect |
| CVE-2026-103754 | 5.9 MEDIUM | Ansible-runner: ansible-runner: path traversal and symlink escape in unstream_dir() allows |
| CVE-2026-103641 | 5.5 MEDIUM | Gegl: gegl04: gegl: out-of-bounds read in the radiance hdr uncompressed scanline decoder |
| CVE-2026-12542 | 5.3 MEDIUM | Foreman: command injection in foreman-tail |
| CVE-2026-56098 | 4.3 MEDIUM | Rubygem-katello: improper authorization logic allows resource enumeration |
No comments yet