Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-3361

Опубликовано: 20 июн. 2023
Источник: redhat
CVSS3: 7.5

Описание

A flaw was found in Red Hat OpenShift Data Science. When exporting a pipeline from the Elyra notebook pipeline editor as Python DSL or YAML, it reads S3 credentials from the cluster (ds pipeline server) and saves them in plain text in the generated output instead of an ID for a Kubernetes secret.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenShift Data Science (RHODS)rhods/odh-dashboard-rhel8Affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-200
https://bugzilla.redhat.com/show_bug.cgi?id=2216588odh-dashboard: s3 credentials included when exporting elyra notebook

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.7
nvd
больше 2 лет назад

A flaw was found in Red Hat OpenShift Data Science. When exporting a pipeline from the Elyra notebook pipeline editor as Python DSL or YAML, it reads S3 credentials from the cluster (ds pipeline server) and saves them in plain text in the generated output instead of an ID for a Kubernetes secret.

CVSS3: 7.7
github
больше 2 лет назад

A flaw was found in Red Hat OpenShift Data Science. When exporting a pipeline from the Elyra notebook pipeline editor as Python DSL or YAML, it reads S3 credentials from the cluster (ds pipeline server) and saves them in plain text in the generated output instead of an ID for a Kubernetes secret.

CVSS3: 7.8
fstec
больше 2 лет назад

Уязвимость редактора электронных таблиц Microsoft Excel, связанная с недостаточной проверкой входных данных, позволяющая нарушителю выполнить произвольный код

7.5 High

CVSS3