Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-h5q4-fjj4-4792

Опубликовано: 23 июл. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

A flaw was found in odh-dashboard, the web console component of Red Hat OpenShift AI (RHOAI). Due to incorrect network binding, a malicious actor within the cluster can bypass authentication and impersonate any user by providing an arbitrary access token. This allows an attacker to gain unauthorized access to the Kubernetes API, potentially leading to arbitrary code execution, privilege escalation, or information disclosure.

A flaw was found in odh-dashboard, the web console component of Red Hat OpenShift AI (RHOAI). Due to incorrect network binding, a malicious actor within the cluster can bypass authentication and impersonate any user by providing an arbitrary access token. This allows an attacker to gain unauthorized access to the Kubernetes API, potentially leading to arbitrary code execution, privilege escalation, or information disclosure.

EPSS

Процентиль: 19%
0.00269
Низкий

8.8 High

CVSS3

Дефекты

CWE-346

Связанные уязвимости

CVSS3: 8.8
redhat
4 месяца назад

A flaw was found in odh-dashboard, the web console component of Red Hat OpenShift AI (RHOAI). Due to incorrect network binding, a malicious actor within the cluster can bypass authentication and impersonate any user by providing an arbitrary access token. This allows an attacker to gain unauthorized access to the Kubernetes API, potentially leading to arbitrary code execution, privilege escalation, or information disclosure.

CVSS3: 8.8
nvd
25 дней назад

A flaw was found in odh-dashboard, the web console component of Red Hat OpenShift AI (RHOAI). Due to incorrect network binding, a malicious actor within the cluster can bypass authentication and impersonate any user by providing an arbitrary access token. This allows an attacker to gain unauthorized access to the Kubernetes API, potentially leading to arbitrary code execution, privilege escalation, or information disclosure.

EPSS

Процентиль: 19%
0.00269
Низкий

8.8 High

CVSS3

Дефекты

CWE-346