高度な大規模言語モデル技術を使用していますが、出力には不正確または古い情報が含まれる可能性があります。Shenlongはデータの正確性を確保するよう努めていますが、実際の状況に基づいて検証・判断してください。
| # | POC説明 | ソースリンク | Shenlongリンク |
|---|
| CVE-2026-50563 | 9.9 CRITICAL | Fission Container Executor Function PodSpec Injection Leading to Node Escape |
| CVE-2026-50566 | 9.9 CRITICAL | Fission: Environment Runtime.Container and Builder.Container SecurityContext bypass allows |
| CVE-2026-50564 | 9.9 CRITICAL | Fission Environment CRD podspec passthrough enables hostPID/hostNetwork/privileged pods, n |
| CVE-2026-46614 | 9.8 CRITICAL | Fission router exposes /fission-function/<ns>/<name> on its public listener, allowing invo |
| CVE-2026-46612 | 8.8 HIGH | Fission StorageSvc /v1/archive endpoint exposes unauthenticated CRUD over all function arc |
| CVE-2026-49824 | 8.5 HIGH | Fission: Cross-namespace Environment reference via unvalidated EnvironmentRef in Function |
| CVE-2026-50570 | 8.5 HIGH | Fission: Incomplete capability denylist in Environment/Function PodSpec validation allows |
| CVE-2026-49823 | 7.7 HIGH | Fission: Cross-namespace Package read via unvalidated PackageRef in Function admission web |
| CVE-2026-49822 | 7.7 HIGH | Fission: Cross-namespace event leakage via KubernetesWatchTrigger allows persistent tenant |
| CVE-2026-49821 | 7.7 HIGH | Fission: Cross-namespace Environment reference in Package allows build-time command execut |
| CVE-2026-50567 | 7.7 HIGH | Fission: Zip Slip in pkg/utils/zip.go:Unarchive allows fetcher to write outside the destin |
| CVE-2026-50565 | 4.9 MEDIUM | Fission builder pods auto-mount the fission-builder ServiceAccount token in the user-suppl |
| CVE-2026-50569 | 4.3 MEDIUM | Fission: HTTPTrigger admission omits RelativeURL / Prefix validation; kubectl apply bypass |
| CVE-2026-50568 | 3.6 LOW | Fission: SanitizeFilePath lexical HasPrefix bypass permits sibling-directory escape |
| CVE-2026-46617 | Fission runtime pods automount the fission-fetcher service-account token into the user fun | |
| CVE-2026-46618 | Fission builder accepts arbitrary buildcmd strings from Environment.spec.builder.command, |
まだコメントはありません