Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-0923

Опубликовано: 15 сент. 2023
Источник: nvd
CVSS3: 8.8
CVSS3: 9.8
EPSS Низкий

Описание

A flaw was found in the Kubernetes service for notebooks in RHODS, where it does not prevent pods from other namespaces and applications from making requests to the Jupyter API. This flaw can lead to file content exposure and other issues.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:a:redhat:openshift_data_science:*:*:*:*:*:*:*:*
Версия от 1.22 (включая) до 1.22.1-3 (исключая)
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*

EPSS

Процентиль: 34%
0.00137
Низкий

8.8 High

CVSS3

9.8 Critical

CVSS3

Дефекты

CWE-862
CWE-862

Связанные уязвимости

CVSS3: 9.8
redhat
почти 3 года назад

A flaw was found in the Kubernetes service for notebooks in RHODS, where it does not prevent pods from other namespaces and applications from making requests to the Jupyter API. This flaw can lead to file content exposure and other issues.

CVSS3: 8
github
больше 2 лет назад

A flaw was found in the Kubernetes service for notebooks in RHODS, where it does not prevent pods from other namespaces and applications from making requests to the Jupyter API. This flaw can lead to file content exposure and other issues.

CVSS3: 8
fstec
почти 3 года назад

Уязвимость службы Kubernetes облачной платформы Red Hat OpenShift Data Science (RHODS), позволяющая нарушителю отправлять произвольные API-запросы

EPSS

Процентиль: 34%
0.00137
Низкий

8.8 High

CVSS3

9.8 Critical

CVSS3

Дефекты

CWE-862
CWE-862