Ose-cluster-ingress-operator: remote code execution through haproxy configuration injection
21Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 8.8epss 0.2%
probabilidad de explotación
0.2%top 91% de las CVE
explotación observada
noninguna fuente lo reporta
The Route OpenShift resource allows to define routes to make pods reachable at a subdomain through HAProxy. It was found that the checks performed on the spec.path YAML stanza in a Route document was insufficient and could allow a controlled injection of the HAProxy configuration.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Productos afectados
Red Hat · Red Hat OpenShift Container Platform 4.13Red Hat · Red Hat OpenShift Container Platform 4.14Red Hat · Red Hat OpenShift Container Platform 4.15Red Hat · Red Hat OpenShift Container Platform 4.16Red Hat · Red Hat OpenShift Container Platform 4.18Red Hat · Red Hat OpenShift Container Platform 4.19Red Hat · Red Hat OpenShift Container Platform 4.20Red Hat · Red Hat OpenShift Container Platform 4.21Referencias
https://access.redhat.com/errata/RHSA-2026:23241https://access.redhat.com/errata/RHSA-2026:23246https://access.redhat.com/errata/RHSA-2026:25045https://access.redhat.com/errata/RHSA-2026:25182https://access.redhat.com/errata/RHSA-2026:25194https://access.redhat.com/errata/RHSA-2026:26543https://access.redhat.com/errata/RHSA-2026:28893https://access.redhat.com/errata/RHSA-2026:28964https://access.redhat.com/security/cve/CVE-2026-1784https://bugzilla.redhat.com/show_bug.cgi?id=2436075https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-1784.json