CVE-2026-71567

In openshift-metal3/fakefish there is a repeated pattern in some of the scripts where shell variables are injected without quoting them either into command lines or into manifests. This mostly applies to the Image URL and BMC credentials (which are not verified by FakeFish).
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-17 15:16

Updated : 2026-09-01 21:03


NVD link : CVE-2026-71567

Mitre link : CVE-2026-71567

CVE.ORG link : CVE-2026-71567


JSON object : View

Products Affected

No product.

CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')