{"id":4791,"date":"2026-02-09T10:34:04","date_gmt":"2026-02-09T02:34:04","guid":{"rendered":"http:\/\/www.gzwangan.com\/?p=4791"},"modified":"2026-02-09T10:38:07","modified_gmt":"2026-02-09T02:38:07","slug":"cve-2026-22822%ef%bc%9aexternal-secrets-operator%e4%b8%a5%e9%87%8d%e6%bc%8f%e6%b4%9e%e7%a0%b4%e5%9d%8f%e5%91%bd%e5%90%8d%e7%a9%ba%e9%97%b4%e9%9a%94%e7%a6%bb%e6%9c%ba%e5%88%b6","status":"publish","type":"post","link":"http:\/\/www.gzwangan.com\/?p=4791","title":{"rendered":"CVE-2026-22822\uff1aExternal Secrets Operator\u4e25\u91cd\u6f0f\u6d1e\u7834\u574f\u547d\u540d\u7a7a\u95f4\u9694\u79bb\u673a\u5236"},"content":{"rendered":"\t\t<div data-elementor-type=\"wp-post\" data-elementor-id=\"4791\" class=\"elementor elementor-4791\" data-elementor-post-type=\"post\">\n\t\t\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-76e2088d elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"76e2088d\" data-element_type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-50 elementor-top-column elementor-element elementor-element-5f77c054\" data-id=\"5f77c054\" data-element_type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<section class=\"elementor-section elementor-inner-section elementor-element elementor-element-5de2a456 elementor-section-full_width elementor-section-height-default elementor-section-height-default\" data-id=\"5de2a456\" data-element_type=\"section\" data-settings=\"{&quot;background_background&quot;:&quot;classic&quot;}\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-inner-column elementor-element elementor-element-23dc6007\" data-id=\"23dc6007\" data-element_type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-3cdb646c elementor-widget elementor-widget-heading\" data-id=\"3cdb646c\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">\u5b89\u5168\u52a8\u6001<\/h2>\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-inner-section elementor-element elementor-element-696ec1ed elementor-section-full_width xi elementor-section-height-default elementor-section-height-default\" data-id=\"696ec1ed\" data-element_type=\"section\" data-settings=\"{&quot;background_background&quot;:&quot;classic&quot;}\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-inner-column elementor-element elementor-element-6a044878\" data-id=\"6a044878\" data-element_type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-5a46d483 elementor-widget elementor-widget-heading\" data-id=\"5a46d483\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\"><a href=\"\/?page_id=561\">\u884c\u4e1a\u52a8\u6001<\/a><\/h2>\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-inner-section elementor-element elementor-element-14ceceab elementor-section-full_width elementor-section-height-default elementor-section-height-default\" data-id=\"14ceceab\" data-element_type=\"section\" data-settings=\"{&quot;background_background&quot;:&quot;classic&quot;}\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-inner-column elementor-element elementor-element-40a212fe\" data-id=\"40a212fe\" data-element_type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-1127c431 elementor-widget elementor-widget-heading\" data-id=\"1127c431\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\"><a href=\"\/?page_id=566\">\u6f0f\u6d1e\u52a8\u6001<\/a><\/h2>\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-inner-section elementor-element elementor-element-467b5338 elementor-section-full_width elementor-section-height-default elementor-section-height-default\" data-id=\"467b5338\" data-element_type=\"section\" data-settings=\"{&quot;background_background&quot;:&quot;classic&quot;}\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-inner-column elementor-element elementor-element-42e8c6e4\" data-id=\"42e8c6e4\" data-element_type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-3f551597 elementor-widget elementor-widget-heading\" data-id=\"3f551597\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">\u8054\u7cfb\u65b9\u5f0f<\/h2>\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-1e687018 elementor-widget elementor-widget-text-editor\" data-id=\"1e687018\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<p>\u5730\u5740\uff1a\u00a0\u5e7f\u5dde\u5e02\u8d8a\u79c0\u533a\u4e1c\u98ce\u4e1c\u8def750\u53f7\u5e7f\u8054\u5927\u53a613\u697c1307-1309\u5ba4<br \/>\u7535\u8bdd\uff1a18898400087<\/p>\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t<div class=\"elementor-column elementor-col-50 elementor-top-column elementor-element elementor-element-7636f30\" data-id=\"7636f30\" data-element_type=\"column\" data-settings=\"{&quot;background_background&quot;:&quot;classic&quot;}\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-2e6adb6a elementor-widget elementor-widget-text-editor\" data-id=\"2e6adb6a\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<section>\n<section>&nbsp; &nbsp; &nbsp; &nbsp;&nbsp;<span leaf=\"\" style=\"caret-color: red; text-indent: 1.75em; visibility: visible;\">External Secrets Operator \u4e2d\u53d1\u73b0\u4e86\u4e00\u4e2a\u4e25\u91cd\u5b89\u5168\u6f0f\u6d1e\u3002\u8be5\u5de5\u5177\u662f Kubernetes \u751f\u6001\u4e2d\u5e7f\u6cdb\u4f7f\u7528\u7684\u5916\u90e8\u5bc6\u94a5\u7ba1\u7406\u7ec4\u4ef6\uff0c\u7528\u4e8e\u8fde\u63a5 AWS Secrets Manager\u3001HashiCorp Vault \u7b49\u5916\u90e8<span link-id=\"link-1770600964534-0.2881228961651714\">\u5bc6\u94a5\u7cfb\u7edf<\/span>\u4e0e Kubernetes \u96c6\u7fa4\u3002<\/span><strong style=\"caret-color: red; text-indent: 1.75em; visibility: visible;\"><span leaf=\"\" style=\"visibility: visible;\">\u6f0f\u6d1e\u7f16\u53f7\u4e3a CVE-2026-22822\uff0cCVSS \u8bc4\u5206\u9ad8\u8fbe 9.3\uff08\u4e25\u91cd\uff09\uff0c\u610f\u5473\u7740\u653b\u51fb\u8005\u53ef\u80fd\u501f\u6b64\u76f4\u63a5\u83b7\u53d6\u654f\u611f\u6570\u636e\u3002<\/span><\/strong><\/section><\/section><section><p style=\"text-indent: 1.75em; visibility: visible;\"><strong style=\"visibility: visible;\"><span style=\"caret-color: red; visibility: visible;\">&nbsp;\u8be5\u6f0f\u6d1e\u5bfc\u81f4 \u4e0d\u5b89\u5168\u7684\u5bc6\u94a5\u8bfb\u53d6\uff08Insecure Secret Retrieval\uff09\uff0c\u5e76\u7834\u574f\u4e86 Kubernetes \u4e2d\u6700\u57fa\u672c\u7684\u547d\u540d\u7a7a\u95f4\u9694\u79bb\u673a\u5236\u3002<\/span><\/strong><span style=\"caret-color: red; visibility: visible;\">\u95ee\u9898\u6e90\u4e8e\u4e00\u4e2a\u540d\u4e3a getSecretKey \u7684<span link-id=\"link-1770600964535-0.7217475636185984\">\u6a21\u677f\u51fd\u6570<\/span>\u3002\u8be5\u51fd\u6570\u6700\u521d\u662f\u4e3a\u4e86\u652f\u6301 senhasegura DevOps Secrets Management (<span link-id=\"link-1770600964543-0.04315435608861784\">DSM<\/span>) \u63d0\u4f9b\u5546\u800c\u5f15\u5165\u7684\uff0c\u4f46\u540e\u6765\u88ab\u53d1\u73b0\u529f\u80fd\u8fc7\u4e8e\u5f3a\u5927\uff0c\u4ece\u800c\u5e26\u6765\u5b89\u5168\u9690\u60a3\u3002<\/span><\/p><p style=\"color: rgb(51, 51, 51); font-size: 16px; font-family: Lato, &quot;Helvetica Neue For Number&quot;, -apple-system, BlinkMacSystemFont, &quot;Segoe UI&quot;, Roboto, &quot;PingFang SC&quot;; visibility: visible;\"><span style=\"font-size: 14px; caret-color: red; visibility: visible;\">\u6839\u636e\u5b89\u5168\u516c\u544a\uff1a\u201c\u8be5\u51fd\u6570\u80fd\u591f\u5728 external-secrets \u63a7\u5236\u5668\u7684 roleBinding \u6743\u9650\u4e0b\u8de8\u547d\u540d\u7a7a\u95f4\u8bfb\u53d6\u5bc6\u94a5\uff0c\u4ece\u800c\u7ed5\u8fc7\u6211\u4eec\u7684\u5b89\u5168\u673a\u5236\u3002\u201d<\/span><\/p><p style=\"text-indent: 0px; color: rgb(51, 51, 51); font-size: 16px; font-family: Lato, &quot;Helvetica Neue For Number&quot;, -apple-system, BlinkMacSystemFont, &quot;Segoe UI&quot;, Roboto, &quot;PingFang SC&quot;; visibility: visible;\"><span style=\"font-size: 14px; caret-color: red; text-indent: 2em;\">&nbsp; &nbsp; &nbsp; &nbsp;\u8fd9\u610f\u5473\u7740\uff0c\u4e00\u4e2a\u547d\u540d\u7a7a\u95f4\u4e2d\u7684\u6076\u610f\u8d44\u6e90\u6216\u914d\u7f6e\u9519\u8bef\u7684\u8d44\u6e90\uff0c\u53ef\u80fd\u8bfb\u53d6\u5230\u53e6\u4e00\u4e2a\u547d\u540d\u7a7a\u95f4\u7684\u5bc6\u94a5\u2014\u2014 \u800c\u8fd9\u4e9b\u5bc6\u94a5\u539f\u672c\u662f\u5b8c\u5168\u4e0d\u5141\u8bb8\u5b83\u8bbf\u95ee\u7684\u3002\u201c\u653b\u51fb\u8005\u6216\u914d\u7f6e\u9519\u8bef\u7684\u8d44\u6e90\u53ef\u4ee5\u4ece\u975e\u9884\u671f\u7684\u547d\u540d\u7a7a\u95f4\u4e2d\u8bfb\u53d6\u5bc6\u94a5\u3002\u201d\u8fd9\u79cd\u7ed5\u8fc7\u7684\u5f71\u54cd\u6781\u4e3a\u4e25\u91cd\u3002\u5982\u679c\u653b\u51fb\u8005\u80fd\u591f\u8bfb\u53d6\u7279\u6743\u547d\u540d\u7a7a\u95f4\u4e2d\u7684\u5bc6\u94a5\uff0c\u4ed6\u4eec\u5c31\u80fd\u8f7b\u677e\u8fdb\u4e00\u6b65\u63d0\u5347\u6743\u9650\u5e76\u5b8c\u5168\u63a7\u5236\u96c6\u7fa4\u3002\u62a5\u544a\u6307\u51fa\uff1a\u201c\u672a\u7ecf\u6388\u6743\u8bbf\u95ee\u5bc6\u94a5\u53ef\u80fd\u5bfc\u81f4\u6743\u9650\u63d0\u5347\u3001\u6570\u636e\u6cc4\u9732\uff0c\u6216\u670d\u52a1\u8d26\u53f7\u4e0e\u51ed\u636e\u88ab\u7a83\u53d6\u3002\u201d<\/span><\/p><p style=\"text-indent: 0px; color: rgb(51, 51, 51); font-size: 16px; font-family: Lato, &quot;Helvetica Neue For Number&quot;, -apple-system, BlinkMacSystemFont, &quot;Segoe UI&quot;, Roboto, &quot;PingFang SC&quot;; visibility: visible;\"><span style=\"font-size: 14px; caret-color: red; text-indent: 2em;\">&nbsp; &nbsp; &nbsp; &nbsp;\u7ba1\u7406\u5458\u5e94\u7acb\u5373\u5ba1\u8ba1\u5176\u96c6\u7fa4\u3002\u8be5\u6f0f\u6d1e\u5f71\u54cd External Secrets Operator \u4ece v0.20.2 \u5230 v1.2.0 \u7684\u6240\u6709\u7248\u672c\u3002\u7ef4\u62a4\u8005\u91c7\u53d6\u4e86\u679c\u65ad\u7684\u4fee\u590d\u65b9\u5f0f\uff1a\u76f4\u63a5\u5220\u9664\u4e86\u8be5\u529f\u80fd\u3002\u201c\u8be5\u51fd\u6570\u5df2\u88ab\u5b8c\u5168\u79fb\u9664\uff0c\u56e0\u4e3a\u5b83\u80fd\u5b9e\u73b0\u7684\u6240\u6709\u529f\u80fd\u90fd\u53ef\u4ee5\u901a\u8fc7\u5176\u4ed6\u65b9\u5f0f\u5b8c\u6210\uff0c\u540c\u65f6\u4e0d\u4f1a\u7834\u574f\u6211\u4eec\u7684\u5b89\u5168\u9632\u62a4\u673a\u5236\u3002\u201d\u7528\u6237\u88ab\u6566\u4fc3\u7acb\u5373\u5347\u7ea7\u5230 v1.2.0 \u7248\u672c\uff0c\u8be5\u7248\u672c\u901a\u8fc7\u5220\u9664\u95ee\u9898\u4ee3\u7801\u5f7b\u5e95\u4fee\u590d\u4e86\u6f0f\u6d1e\u3002<\/span><\/p><p style=\"text-indent: 0px; color: rgb(51, 51, 51); font-size: 16px; font-family: Lato, &quot;Helvetica Neue For Number&quot;, -apple-system, BlinkMacSystemFont, &quot;Segoe UI&quot;, Roboto, &quot;PingFang SC&quot;; visibility: visible;\"><span style=\"font-size: 14px; caret-color: red; text-indent: 2em;\">&nbsp; &nbsp; &nbsp; &nbsp;\u5bf9\u4e8e\u6682\u65f6\u65e0\u6cd5\u5347\u7ea7\u7684\u7528\u6237\uff0c\u4e5f\u6709\u4e34\u65f6\u7f13\u89e3\u65b9\u6848\u3002\u7ba1\u7406\u5458\u53ef\u4ee5\u4f7f\u7528 Kyverno\u3001Kubewarden \u6216 OPA \u7b49\u7b56\u7565\u5f15\u64ce\u6765 \u201c\u963b\u6b62\u5728\u4efb\u4f55 ExternalSecret \u8d44\u6e90\u4e2d\u4f7f\u7528 getSecretKey \u51fd\u6570\u201d\u3002<\/span><\/p>\n<\/section>\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<\/div>\n\t\t","protected":false},"excerpt":{"rendered":"<p>\u5b89\u5168\u52a8\u6001 \u884c\u4e1a\u52a8\u6001 \u6f0f\u6d1e\u52a8\u6001 \u8054\u7cfb\u65b9\u5f0f \u5730\u5740\uff1a\u00a0\u5e7f\u5dde\u5e02\u8d8a\u79c0\u533a\u4e1c\u98ce\u4e1c\u8def750\u53f7\u5e7f\u8054\u5927\u53a613\u697c1307-1309\u5ba4&hellip; <a class=\"more-link\" href=\"http:\/\/www.gzwangan.com\/?p=4791\">\u7ee7\u7eed\u9605\u8bfb<span class=\"screen-reader-text\">CVE-2026-22822\uff1aExternal Secrets Operator\u4e25\u91cd\u6f0f\u6d1e\u7834\u574f\u547d\u540d\u7a7a\u95f4\u9694\u79bb\u673a\u5236<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"","sticky":false,"template":"elementor_header_footer","format":"standard","meta":{"footnotes":""},"categories":[5],"tags":[],"class_list":["post-4791","post","type-post","status-publish","format-standard","hentry","category-security","entry"],"_links":{"self":[{"href":"http:\/\/www.gzwangan.com\/index.php?rest_route=\/wp\/v2\/posts\/4791","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.gzwangan.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.gzwangan.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.gzwangan.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"http:\/\/www.gzwangan.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=4791"}],"version-history":[{"count":5,"href":"http:\/\/www.gzwangan.com\/index.php?rest_route=\/wp\/v2\/posts\/4791\/revisions"}],"predecessor-version":[{"id":4797,"href":"http:\/\/www.gzwangan.com\/index.php?rest_route=\/wp\/v2\/posts\/4791\/revisions\/4797"}],"wp:attachment":[{"href":"http:\/\/www.gzwangan.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=4791"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.gzwangan.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=4791"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.gzwangan.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=4791"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}