Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-66805

Опубликовано: 10 авг. 2026
Источник: redhat
CVSS3: 8
EPSS Низкий

Описание

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

A flaw was found in the console component. An attacker who can write to container logs on a managed cluster can inject malicious code into the hub console user's browser session. This occurs when the user views raw pod logs, as the console does not properly escape the log content. Successful exploitation could lead to session hijacking, credential theft, or unauthorized actions performed on behalf of the console user.

Отчет

This is an Important flaw where an attacker with the ability to write to container logs on a managed cluster can inject malicious HTML/JavaScript. When a Red Hat Advanced Cluster Management for Kubernetes console user views these raw pod logs, the injected code executes in their browser session, potentially leading to session hijacking or credential theft. Exploitation requires both attacker control over pod output and specific user interaction.

Меры по смягчению последствий

To reduce the risk of exploitation, ensure strict access controls are enforced on managed clusters, limiting the ability of untrusted users to deploy or modify pods and thus inject malicious content into container logs. Additionally, users should exercise caution when viewing "Raw" logs from potentially untrusted sources within the hub console.

Дополнительная информация

Статус:

Important
Дефект:
CWE-79
https://bugzilla.redhat.com/show_bug.cgi?id=2508666console: console: stored DOM XSS via unescaped pod logs in document.write

EPSS

Процентиль: 78%
0.01906
Низкий

8 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
nvd
8 дней назад

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

CVSS3: 8.8
msrc
8 дней назад

Microsoft SharePoint Server Remote Code Execution Vulnerability

CVSS3: 8.8
github
8 дней назад

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

EPSS

Процентиль: 78%
0.01906
Низкий

8 High

CVSS3