目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1325

100%

CVE-2026-7163— Red Hat assisted-service 安全漏洞

CVSS 6.1 · Medium EPSS 0.16% · P5

影响版本矩阵 6

厂商产品版本范围状态
Red Hatmulticluster engine for Kubernetes 2.101776983527< *unaffected
Red Hatmulticluster engine for Kubernetes 2.111776987609< *unaffected
Red Hatmulticluster engine for Kubernetes 2.71777205801< *unaffected
1777205772< *unaffected
Red Hatmulticluster engine for Kubernetes 2.91778464111< *unaffected
1778464072< *unaffected
获取后续新漏洞提醒登录后订阅

一、 漏洞 CVE-2026-7163 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
Assisted-service: assisted-service: authenticated users can gain administrative access to openshift clusters via credential disclosure
来源: 美国国家漏洞数据库 NVD
Vulnerability Description
A vulnerability in the assisted-service REST API, an optional Assisted Installer (assisted-service) component in the Multicluster Engine (MCE), allows an authenticated user with minimal namespace-scoped privileges to obtain administrative credentials for arbitrary clusters provisioned through the hub. The credentials download endpoint (GET /v2/clusters/{cluster_id}/credentials, which returns the kubeadmin password) and the kubeconfig download endpoint are operational in AUTH_TYPE=local mode, the only authentication mode available in on-premises ACM/MCE hub deployments. The local authenticator unconditionally grants full administrative access to any request bearing a valid JWT, with no per-endpoint restrictions. A valid local JWT is embedded as a plaintext query parameter in InfraEnvStatus.ISODownloadURL and is readable by any user who has get rights on an InfraEnv object in their own namespace. The affected components ship as part of Multicluster Engine (MCE). The Red Hat Advanced Cluster Management (ACM) deployments that include MCE are equally affected. This issue does not affect the hosted SaaS offering (console.redhat.com), which uses a different authentication mode. Successful exploitation gives the attacker the kubeadmin password and kubeconfig for any OpenShift cluster provisioned through the affected hub, granting unrestricted root-level administrative access to those spoke clusters.
来源: 美国国家漏洞数据库 NVD
CVSS Information
CVSS:3.1/AV:A/AC:L/PR:L/UI:R/S:C/C:H/I:N/A:N
来源: 美国国家漏洞数据库 NVD
Vulnerability Type
敏感数据的明文存储
来源: 美国国家漏洞数据库 NVD
Vulnerability Title
Red Hat assisted-service 安全漏洞
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Description
Red Hat assisted-service是美国红帽(Red Hat)公司的一个提供 REST API 的后端服务组件,主要服务于OpenShift生态系统。 Red Hat assisted-service存在安全漏洞,该漏洞源于assisted-service REST API组件在AUTH_TYPE=local模式下无条件授予JWT持有者完全管理权限,可能导致经过身份验证的用户获取通过中心配置的任意集群的管理员凭据。
来源: 中国国家信息安全漏洞库 CNNVD
CVSS Information
N/A
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Type
N/A
来源: 中国国家信息安全漏洞库 CNNVD

受影响产品

厂商产品影响版本CPE订阅
Red Hatmulticluster engine for Kubernetes 2.10 1776983527 ~ * cpe:/a:redhat:multicluster_engine:2.10::el9
Red Hatmulticluster engine for Kubernetes 2.11 1776987609 ~ * cpe:/a:redhat:multicluster_engine:2.11::el9
Red Hatmulticluster engine for Kubernetes 2.7 1777205801 ~ * cpe:/a:redhat:multicluster_engine:2.7::el8
Red Hatmulticluster engine for Kubernetes 2.7 1777205772 ~ * cpe:/a:redhat:multicluster_engine:2.7::el9
Red Hatmulticluster engine for Kubernetes 2.9 1778464111 ~ * cpe:/a:redhat:multicluster_engine:2.9::el8
Red Hatmulticluster engine for Kubernetes 2.9 1778464072 ~ * cpe:/a:redhat:multicluster_engine:2.9::el9

二、漏洞 CVE-2026-7163 的公开POC

#POC 描述源链接神龙链接
AI 生成 POC高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2026-7163 的情报信息

登录查看更多情报信息。

CVE-2026-7163 厂商安全公告 (5)

IV. Related Vulnerabilities

V. Comments for CVE-2026-7163

暂无评论


发表评论