Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gj4f-3qq5-j78j

Опубликовано: 04 окт. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 7.7

Описание

A flaw was found in Red Hat OpenShift Data Science. When exporting a pipeline from the Elyra notebook pipeline editor as Python DSL or YAML, it reads S3 credentials from the cluster (ds pipeline server) and saves them in plain text in the generated output instead of an ID for a Kubernetes secret.

A flaw was found in Red Hat OpenShift Data Science. When exporting a pipeline from the Elyra notebook pipeline editor as Python DSL or YAML, it reads S3 credentials from the cluster (ds pipeline server) and saves them in plain text in the generated output instead of an ID for a Kubernetes secret.

EPSS

Процентиль: 12%
0.00041
Низкий

7.7 High

CVSS3

Дефекты

CWE-200
CWE-319

Связанные уязвимости

CVSS3: 7.5
redhat
больше 2 лет назад

A flaw was found in Red Hat OpenShift Data Science. When exporting a pipeline from the Elyra notebook pipeline editor as Python DSL or YAML, it reads S3 credentials from the cluster (ds pipeline server) and saves them in plain text in the generated output instead of an ID for a Kubernetes secret.

CVSS3: 7.7
nvd
больше 2 лет назад

A flaw was found in Red Hat OpenShift Data Science. When exporting a pipeline from the Elyra notebook pipeline editor as Python DSL or YAML, it reads S3 credentials from the cluster (ds pipeline server) and saves them in plain text in the generated output instead of an ID for a Kubernetes secret.

CVSS3: 7.8
fstec
больше 2 лет назад

Уязвимость редактора электронных таблиц Microsoft Excel, связанная с недостаточной проверкой входных данных, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 12%
0.00041
Низкий

7.7 High

CVSS3

Дефекты

CWE-200
CWE-319