Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-0923

Опубликовано: 28 фев. 2023
Источник: redhat
CVSS3: 9.8
EPSS Низкий

Описание

A flaw was found in the Kubernetes service for notebooks in RHODS, where it does not prevent pods from other namespaces and applications from making requests to the Jupyter API. This flaw can lead to file content exposure and other issues.

Дополнительная информация

Статус:

Important
Дефект:
CWE-862
https://bugzilla.redhat.com/show_bug.cgi?id=2171870odh-notebook-controller-container: Missing authorization allows for file contents disclosure

EPSS

Процентиль: 34%
0.00137
Низкий

9.8 Critical

CVSS3

Связанные уязвимости

CVSS3: 8.8
nvd
больше 2 лет назад

A flaw was found in the Kubernetes service for notebooks in RHODS, where it does not prevent pods from other namespaces and applications from making requests to the Jupyter API. This flaw can lead to file content exposure and other issues.

CVSS3: 8
github
больше 2 лет назад

A flaw was found in the Kubernetes service for notebooks in RHODS, where it does not prevent pods from other namespaces and applications from making requests to the Jupyter API. This flaw can lead to file content exposure and other issues.

CVSS3: 8
fstec
почти 3 года назад

Уязвимость службы Kubernetes облачной платформы Red Hat OpenShift Data Science (RHODS), позволяющая нарушителю отправлять произвольные API-запросы

EPSS

Процентиль: 34%
0.00137
Низкий

9.8 Critical

CVSS3