🛡️ CVE Monitor
Dịch vụ / phần mềm liên quan: Chưa phân loại — không khớp danh sách dịch vụ/phần mềm đang theo dõi (xem/thêm ở internal/cve/categories.go), hoặc NVD chưa cung cấp đủ dữ liệu vendor/sản phẩm cho CVE này.

Mô tả

An OS command injection flaw was found in the set_hostname_internal function of NooBaa's cluster_internal_api. This component is responsible for managing the Multi-Cloud Object Gateway in OpenShift Data Foundation. The vulnerability occurs because the hostname parameter is passed directly to a shell command without proper sanitization. An authenticated attacker with administrative privileges can provide a specially crafted hostname containing shell metacharacters to execute arbitrary commands on the host system with the privileges of the NooBaa process.

Chi tiết

Trạng tháiReceived
Điểm CVSS7.2 (v3.1)
Vector CVSSCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Ngày công bố20:17 28/09/2026
Ngày cập nhật20:17 28/09/2026
Nguồn dữ liệunvd

CWE

  • CWE-78

Sản phẩm bị ảnh hưởng

Nguồn dữ liệu chưa cung cấp thông tin sản phẩm chi tiết.

Tài liệu tham khảo

Lịch sử thay đổi

Thời gianLoạiTrườngGiá trị cũGiá trị mới
20:17 28/09/2026 CREATED cve HIGH

Tất cả thời gian trên trang này hiển thị theo giờ Việt Nam (GMT+7).