PT-2026-106190 · Red Hat · Multicluster Engine For Kubernetes
CVE-2026-71298
·
Publicado
2026-10-05
·
Atualizado
2026-10-05
CVSS v3.1
6.4
Média
| Vetor | AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:L |
A flaw was found in maestro. A remote attacker could exploit a SQL injection vulnerability in the
orderBy query parameter of its REST API list endpoints. This flaw, which does not require authentication, allows for read-only blind extraction of data from the database.Correção
SQL injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Multicluster Engine For Kubernetes