Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-5483

Опубликовано: 10 апр. 2026
Источник: nvd
CVSS3: 8.5
CVSS3: 9.9
EPSS Низкий

Описание

A flaw was found in odh-dashboard in Red Hat Openshift AI. This vulnerability in the odh-dashboard component of Red Hat OpenShift AI (RHOAI) allows for the disclosure of Kubernetes Service Account tokens through a NodeJS endpoint. This could enable an attacker to gain unauthorized access to Kubernetes resources.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:redhat:openshift_ai:*:*:*:*:*:*:*:*
Версия от 2.16 (включая) до 2.16.4 (исключая)
cpe:2.3:a:redhat:openshift_ai:*:*:*:*:*:*:*:*
Версия от 2.25 (включая) до 2.25.4 (исключая)
cpe:2.3:a:redhat:openshift_ai:3.2:*:*:*:*:*:*:*
cpe:2.3:a:redhat:openshift_ai:3.3:*:*:*:*:*:*:*

EPSS

Процентиль: 40%
0.00492
Низкий

8.5 High

CVSS3

9.9 Critical

CVSS3

Дефекты

CWE-201
CWE-201

Связанные уязвимости

CVSS3: 8.5
redhat
4 месяца назад

A flaw was found in odh-dashboard in Red Hat Openshift AI. This vulnerability in the `odh-dashboard` component of Red Hat OpenShift AI (RHOAI) allows for the disclosure of Kubernetes Service Account tokens through a NodeJS endpoint. This could enable an attacker to gain unauthorized access to Kubernetes resources.

CVSS3: 8.5
github
4 месяца назад

A flaw was found in odh-dashboard in Red Hat Openshift AI. This vulnerability in the `odh-dashboard` component of Red Hat OpenShift AI (RHOAI) allows for the disclosure of Kubernetes Service Account tokens through a NodeJS endpoint. This could enable an attacker to gain unauthorized access to Kubernetes resources.

EPSS

Процентиль: 40%
0.00492
Низкий

8.5 High

CVSS3

9.9 Critical

CVSS3

Дефекты

CWE-201
CWE-201