Описание
A flaw was found in the Red Hat OpenShift AI (RHOAI) MaaS Gateway. Improper configuration of the Gateway in a model-serving context allows a standard user with low privileges to intercept, read, log, and alter all MaaS model traffic. This includes sensitive information such as access keys, input prompts, and outputs, leading to significant information disclosure and data tampering.
Отчет
This Important flaw in the Red Hat OpenShift AI (RHOAI) MaaS Gateway stems from an insecure default configuration, allowing a standard user with low privileges to intercept, read, log, and alter all model-serving traffic. This includes sensitive data such as access keys, input prompts, and outputs, leading to significant information disclosure and data tampering within any namespace authorized to use the MaaS Gateway.
Меры по смягчению последствий
You can restrict Gateway access to some namespaces only. However, it does not prevent someone from an authorized namespace to hijack the traffic of another. Fully locking down access to the MaaS Gateway is a solution, however it defeats the self-service approach of the component.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-kserve-controller-rhel9 | Affected | ||
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-kserve-llmisvc-controller-rhel9 | Affected | ||
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-maas-controller-rhel9 | Affected | ||
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-mod-arch-maas-rhel9 | Affected | ||
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-model-controller-rhel9 | Affected | ||
| Red Hat OpenShift AI 3.4 | rhoai/odh-rhel9-operator | Fixed | RHSA-2026:53262 | 11.08.2026 |
Показывать по
Дополнительная информация
Статус:
EPSS
8.8 High
CVSS3
Связанные уязвимости
A flaw was found in the Red Hat OpenShift AI (RHOAI) MaaS Gateway. Improper configuration of the Gateway in a model-serving context allows a standard user with low privileges to intercept, read, log, and alter all MaaS model traffic. This includes sensitive information such as access keys, input prompts, and outputs, leading to significant information disclosure and data tampering.
A flaw was found in the Red Hat OpenShift AI (RHOAI) MaaS Gateway. Improper configuration of the Gateway in a model-serving context allows a standard user with low privileges to intercept, read, log, and alter all MaaS model traffic. This includes sensitive information such as access keys, input prompts, and outputs, leading to significant information disclosure and data tampering.
EPSS
8.8 High
CVSS3