Kubevirt是KubeVirt开源的一款虚拟机管理器。 KubeVirt存在后置链接漏洞,该漏洞源于VMExport目录端点中的路径遍历问题,可能导致具有特定命名空间级别访问权限的攻击者通过在被导出的文件系统持久卷声明中放置指向其指定挂载根目录之外的符号链接,读取导出器Pod文件系统中的任意文件,从而导致信息泄露。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Red Hat | Red Hat Container Native Virtualization 4.17 | 1781757410< * |
unaffected |
| Red Hat | Red Hat Container Native Virtualization 4.18 | 1781928221< * |
unaffected |
| Red Hat | Red Hat Container Native Virtualization 4.19 | 1781590993< * |
unaffected |
| Red Hat | Red Hat Container Native Virtualization 4.20 | 1781838712< * |
unaffected |
| Red Hat | Red Hat Container Native Virtualization 4.21 | 1782012918< * |
unaffected |
| Red Hat | Red Hat OpenShift Virtualization 4 | any |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat Container Native Virtualization 4.17 | 1781757410 ~ * |
cpe:/a:redhat:container_native_virtualization:4.17::el9
|
|
| Red Hat | Red Hat Container Native Virtualization 4.18 | 1781928221 ~ * |
cpe:/a:redhat:container_native_virtualization:4.18::el9
|
|
| Red Hat | Red Hat Container Native Virtualization 4.19 | 1781590993 ~ * |
cpe:/a:redhat:container_native_virtualization:4.19::el9
|
|
| Red Hat | Red Hat Container Native Virtualization 4.20 | 1781838712 ~ * |
cpe:/a:redhat:container_native_virtualization:4.20::el9
|
|
| Red Hat | Red Hat Container Native Virtualization 4.21 | 1782012918 ~ * |
cpe:/a:redhat:container_native_virtualization:4.21::el9
|
|
| Red Hat | Red Hat OpenShift Virtualization 4 | - |
cpe:/a:redhat:container_native_virtualization:4
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-4408 | 9.0 CRITICAL | Samba: remote code execution in samr |
| CVE-2026-9795 | 7.3 HIGH | Keycloak: keycloak: privilege escalation via improper scope mapping enforcement |
| CVE-2026-44604 | 7.0 HIGH | Rpm: command injection in rpmuncompress dountar() via unescaped archive top-level director |
| CVE-2026-9802 | 6.8 MEDIUM | Keycloak: keycloak: unauthorized account access via replayed refresh tokens after cluster |
| CVE-2026-9792 | 6.5 MEDIUM | Keycloak: keycloak: security restriction bypass allows unauthorized ropc token acquisition |
| CVE-2026-9796 | 6.5 MEDIUM | Keycloak: keycloak: privilege escalation via time-of-check to time-of-use (toctou) vulnera |
| CVE-2026-9793 | 5.9 MEDIUM | Keycloak: keycloak: security policy bypass in jwe-encrypted request object processing |
| CVE-2026-9794 | 5.3 MEDIUM | Keycloak: keycloak: information disclosure via saml ecp endpoint |
| CVE-2026-9803 | 5.3 MEDIUM | Keycloak: keycloak: denial of service via malformed authorization header |
| CVE-2026-9801 | 4.9 MEDIUM | Keycloak: keycloak: denial of service via malformed ldap password policy response |
| CVE-2026-9791 | 4.3 MEDIUM | Keycloak-rhel9: organization data leak after feature disabled in keycloak |
| CVE-2026-9798 | 4.3 MEDIUM | Keycloak: keycloak: brute-force protection bypass in ciba flow |
| CVE-2026-10028 | 4.3 MEDIUM | Glib-networking: infinite loop in glib-networking gnutls backend allows remote denial of s |
No comments yet