Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
–

29 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisAlta (7.7)0.53%—Redhat Advanced Cluster ManagementAIRedhat Multicloud Operators SubscriptionAI20/8/202628/8/2026
A flaw was found in the multicloud-operators-subscription component of Red Hat Advanced Cluster Management (RHACM). A tenant with HelmRelease create permissions can exploit this vulnerability by manipulating the `secretRef.Namespace` field. This allows the `GetSecret()` function in the HelmRelease controller to fetch…
Pendiente de análisisMedia (5.4)0.35%—Redhat Advanced Cluster Management FOR KubernetesAI20/8/20263/9/2026
A flaw was found in the lighthouse component of Red Hat Advanced Cluster Management for Kubernetes. This vulnerability stems from insufficient validation of advertised IP addresses within EndpointSlice objects. A compromised spoke cluster can exploit this by creating EndpointSlices with attacker-controlled IP…
Pendiente de análisisMedia (4.4)0.35%—Submariner-operatorAIRedhat Advanced Cluster Management FOR KubernetesAI18/8/20263/9/2026
A flaw was found in the `submariner-operator` component of Red Hat Advanced Cluster Management for Kubernetes. This vulnerability allows a cluster administrator, or any user with permissions to modify the Submariner Custom Resource (CR), to specify an unvalidated image path. This lack of validation enables an attacker…
Pendiente de análisisMedia (5.5)0.19%—Redhat Advanced Cluster Management FOR KubernetesAI18/8/20265/9/2026
A flaw was found in the must-gather component of Red Hat Advanced Cluster Management for Kubernetes. The cluster Proxy object is dumped in raw form, bypassing the oc inspect redaction that would normally sanitize sensitive fields. This exposes proxy basic-auth credentials in the must-gather archive, potentially…
Pendiente de análisisMedia (5.5)0.11%—Redhat Advanced Cluster Management FOR KubernetesAI18/8/20265/9/2026
A flaw was found in the must-gather component of Red Hat Advanced Cluster Management for Kubernetes. Certain ACM wrapper Custom Resources that embed Secret data are collected without redaction. When an administrator runs must-gather, credentials and tokens are captured in cleartext in the resulting archive,…
Pendiente de análisisAlta (8.8)0.81%—Redhat Advanced Cluster Management FOR KubernetesAIRedhat Governance Policy Addon ControllerAI18/8/202627/8/2026
A flaw was found in the governance-policy-addon-controller component of Red Hat Advanced Cluster Management for Kubernetes. A user with permissions to annotate the namespaced ManagedClusterAddOn resource can override the governance-policy container image. This allows an attacker to run a controlled image with…
ModificadaMedia (6.5)0.16%—Redhat Advanced Cluster Management FOR KubernetesRedhat Insights-client12/8/20265/9/2026
A flaw was found in insights-client. The component's ServiceAccount is bound to a ClusterRole granting cluster-wide secrets get, list, and watch permissions, while the code only requires access to a single specific Secret. This excessive privilege means that a compromise of the insights-client pod or ServiceAccount…
Pendiente de análisisCrítica (9.9)0.81%—Redhat Advanced Cluster ManagementAI12/8/202627/8/2026
A flaw was found in the multicloud-operators-subscription component of Red Hat Advanced Cluster Management (RHACM). This vulnerability allows a namespace-admin tenant to perform a confused-deputy attack by creating Subscription Custom Resources (CRs) that leverage a highly privileged ServiceAccount (SA). This enables…
Pendiente de análisisAlta (7.7)0.48%—Redhat Advanced Cluster ManagementAIRedhat Multicloud Operators ChannelAI12/8/202627/8/2026
A flaw was found in the multicloud-operators-channel component of Red Hat Advanced Cluster Management (RHACM). This vulnerability allows a compromised agent from a managed cluster to gain unauthorized access to sensitive information. Specifically, the agent can read all Secrets and ConfigMaps within any Channel…
Pendiente de análisisCrítica (9.6)0.52%—Argoproj ArgocdAIRedhat Advanced Cluster ManagementAIRedhat Multicloud IntegrationsAI12/8/202627/8/2026
A flaw was found in multicloud-integrations, a component of Red Hat Advanced Cluster Management (RHACM). This vulnerability allows an authenticated user, referred to as a tenant, to manipulate the GitOpsCluster controller. By exploiting this, a tenant can redirect sensitive spoke cluster bearer tokens from secure…
ModificadaAlta (7.7)0.50%—Redhat Advanced Cluster Management FOR KubernetesRedhat Insights-client11/8/20265/9/2026
A flaw was found in insights-client. The setDefault() function logs the value of every environment variable it processes, including CCX_TOKEN, a bearer credential used in disconnected cluster deployments. When glog verbosity is set to level 2 or higher, the token is written in clear text to the pod log on every…
ModificadaMedia (6.8)0.69%—Redhat Advanced Cluster Management FOR KubernetesRedhat Insights-client11/8/20265/9/2026
A flaw was found in insights-client. A compromised managed cluster, referred to as a 'spoke', can inject unencoded data into the Insights API URL path. This occurs because the ClusterID, which is controlled by the spoke, is used directly in the request path without proper validation or URL encoding. This vulnerability…
ModificadaMedia (6.5)0.16%—Redhat Advanced Cluster Management FOR KubernetesRedhat Insights-client11/8/20265/9/2026
A flaw was found in insights-client. When the application receives a non-200 response, it logs the request headers, which can include the cloud.openshift.com pull-secret token. A local user with access to pod logs on the hub could read this long-lived credential. This information disclosure could grant unauthorized…
Pendiente de análisisCrítica (9)0.58%—Redhat Advanced Cluster Management FOR KubernetesAI5/8/20268/9/2026
A flaw was found in the Application Subscription controller (multicluster-operators-subscription) of Red Hat Advanced Cluster Management for Kubernetes (ACM). A user with namespace-scoped "edit" privileges in an ACM hub namespace can create a Channel resource pointing to a Helm repository they control and a…
Pendiente de análisisAlta (8.5)0.57%—Redhat Advanced Cluster Management FOR KubernetesAIRedhat Multicluster-engineAI24/7/202629/9/2026
A flaw was found in the cluster-proxy service-proxy component used in Red Hat Advanced Cluster Management for Kubernetes (RHACM) and multicluster-engine (MCE). The service-proxy appends impersonation group headers to proxied requests without first removing caller-supplied values, and the spoke ServiceAccount holds…
ModificadaAlta (7.7)1.0%—AxiosRedhat Advanced Cluster Management FOR KubernetesRedhat Advanced Cluster SecurityRedhat Ansible Automation Platform+811/6/202611/9/2026
Axios is a promise based HTTP client for the browser and Node.js. From 0.19.0 to before 0.31.1 and 1.15.2, Axios contains prototype-pollution gadgets in request config processing. If another vulnerability in the same JavaScript process has already polluted Object.prototype.transformResponse, affected Axios versions…
AnalizadaMedia (6.7)0.11%—Redhat Advanced Cluster Management FOR Kubernetes8/4/202624/7/2026
A container privilege escalation flaw was found in certain Multicluster Engine for Kubernetes images. This issue stems from the /etc/passwd file being created with group-writable permissions during build time. In certain conditions, an attacker who can execute commands within an affected container, even as a non-root…
ModificadaAlta (8.2)0.16%—Redhat Advanced Cluster Management FOR Kubernetes7/4/20268/9/2026
A flaw was found in Open Cluster Management (OCM), the technology underlying Red Hat Advanced Cluster Management (ACM). Improper validation of Kubernetes client certificate renewal allows a managed cluster administrator to forge a client certificate that can be approved by the OCM controller. This enables…
ModificadaAlta (7.5)0.56%—NodemailerRedhat Advanced Cluster Management FOR KubernetesRedhat Ceph StorageRedhat Developer HUB18/12/202530/9/2026
A flaw was found in Nodemailer. This vulnerability allows a denial of service (DoS) via a crafted email address header that triggers infinite recursion in the address parser.
AnalizadaMedia (5.5)0.14%—Redhat Advanced Cluster Management FOR Kubernetes2/7/202517/6/2026
A flaw was found in Red Hat Advanced Cluster Management through versions 2.10, before 2.10.7, 2.11, before 2.11.4, and 2.12, before 2.12.4. This vulnerability allows an unprivileged user to view confidential managed cluster credentials through the UI. This information should only be accessible to authorized users and…
AplazadaAlta (8.2)0.49%—Redhat Multicluster EngineAIRedhat Advanced Cluster ManagementAIRedhat HiveAI17/3/202521/8/2026
A flaw was found in Hive, a component of Multicluster Engine (MCE) and Advanced Cluster Management (ACM). This vulnerability causes VCenter credentials to be exposed in the ClusterProvision object after provisioning a VSphere cluster. Users with read access to ClusterProvision objects can extract sensitive credentials…
AnalizadaAlta (7.5)100%⚠ Explotación activa💥 ExploitSiemens Simatic S7-1500 CPU 1518f-4 Pn/dp MFP FirmwareSiemens Sinec INSSiemens Sinec NMSSiemens ST7 Scadaconnect+16110/10/202311/8/2026
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
ModificadaAlta (7.5)0.48%—Redhat Advanced Cluster Management FOR KubernetesRedhat Openshift Container Platform5/10/202317/6/2026
A flaw was found in OpenShift API, as admission checks do not enforce "custom-host" permissions. This issue could allow an attacker to violate the boundaries, as permissions will not be applied.
ModificadaAlta (7.8)0.20%—Redhat Advanced Cluster Management FOR Kubernetes5/6/202317/6/2026
The grc-policy-propagator allows security escalation within the cluster. The propagator allows policies which contain some dynamically obtained values (instead of the policy apply a static manifest on a managed cluster) of taking advantage of cluster scoped access in a created policy. This feature does not restrict…
ModificadaAlta (7.8)0.23%—Redhat Advanced Cluster Management FOR Kubernetes13/1/202317/6/2026
RHACM: unauthenticated SSRF in console API endpoint. A Server-Side Request Forgery (SSRF) vulnerability was found in the console API endpoint from Red Hat Advanced Cluster Management for Kubernetes (RHACM). An attacker could take advantage of this as the console API endpoint is missing an authentication check,…
Orbitaley — Vulnerabilidades