Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gj4f-3qq5-j78j

Опубликовано: 04 окт. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 7.7

Описание

A flaw was found in Red Hat OpenShift Data Science. When exporting a pipeline from the Elyra notebook pipeline editor as Python DSL or YAML, it reads S3 credentials from the cluster (ds pipeline server) and saves them in plain text in the generated output instead of an ID for a Kubernetes secret.

A flaw was found in Red Hat OpenShift Data Science. When exporting a pipeline from the Elyra notebook pipeline editor as Python DSL or YAML, it reads S3 credentials from the cluster (ds pipeline server) and saves them in plain text in the generated output instead of an ID for a Kubernetes secret.

EPSS

Процентиль: 39%
0.0047
Низкий

7.7 High

CVSS3

Дефекты

CWE-200
CWE-319

Связанные уязвимости

CVSS3: 7.5
redhat
около 3 лет назад

A flaw was found in Red Hat OpenShift Data Science. When exporting a pipeline from the Elyra notebook pipeline editor as Python DSL or YAML, it reads S3 credentials from the cluster (ds pipeline server) and saves them in plain text in the generated output instead of an ID for a Kubernetes secret.

CVSS3: 7.7
nvd
почти 3 года назад

A flaw was found in Red Hat OpenShift Data Science. When exporting a pipeline from the Elyra notebook pipeline editor as Python DSL or YAML, it reads S3 credentials from the cluster (ds pipeline server) and saves them in plain text in the generated output instead of an ID for a Kubernetes secret.

CVSS3: 7.8
fstec
около 3 лет назад

Уязвимость редактора электронных таблиц Microsoft Excel, связанная с недостаточной проверкой входных данных, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 39%
0.0047
Низкий

7.7 High

CVSS3

Дефекты

CWE-200
CWE-319