在 StreamsHub 控制台中发现了一个漏洞,该漏洞涉及 Apache Kafka 的流处理控制台。控制台的自定义资源(Console Custom Resource)中由租户提供的 Kafka 客户端属性被直接复制到 console-api 的 AdminClient 配置中,而没有对安全性敏感的配置键进行过滤。这允许控制台自定义资源(Console CR)的编写者设置 和 ,从而将 console-api 服务账号(ServiceAccount)的令牌外泄到攻击者控制的 Kafka Broker 中。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Red Hat | streams for Apache Kafka 2 | any |
affected |
| Red Hat | streams for Apache Kafka 3 | any |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | streams for Apache Kafka 2 | - |
cpe:/a:redhat:amq_streams:2
|
|
| Red Hat | streams for Apache Kafka 3 | - |
cpe:/a:redhat:amq_streams:3
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-101292 | 8.2 HIGH | Artemis-core-client: unsafe reflection in apache activemq artemis federation message deser |
| CVE-2026-86330 | 7.2 HIGH | Noobaa-core: noobaa-core: os command injection in cluster_internal_api.set_hostname_intern |
| CVE-2026-97023 | 7.1 HIGH | Flatpak: flatpak: arbitrary file deletion in root context via path traversal in deploy dir |
| CVE-2026-87114 | 7.1 HIGH | Kube-compare: container:// reference extraction runs the image entrypoint and silently esc |
| CVE-2026-102010 | 7.0 HIGH | Gcc-toolset-15-gcc: gcc: gcc-toolset-16: gcc: denial of service via use-after-free in bina |
| CVE-2026-97026 | 3.9 LOW | Flatpak: flatpak: world-writable temporary child repositories in system-helper cache path |
| CVE-2026-101333 | 3.7 LOW | Keycloak-services: keycloak-services: unbounded metric series creation via idp tag on brok |
| CVE-2026-97027 | 3.6 LOW | Flatpak: flatpak: denial of service via unsanitized keys in exported desktop entry / d-bus |
| CVE-2026-97025 | 3.2 LOW | Flatpak: flatpak: world-readable oci authentication token in system-helper cache path |
No comments yet