Описание
The SimpleRBACAuthorizationProvider authorization provider in versions 0.5.0 or later of the ChromaDB Python project evaluates whether a user holds a given permission but never checks which tenant, database, or collection that permission applies to allowing users to perform cross tenant actions.
A flaw was found in the SimpleRBACAuthorizationProvider authorization provider in the ChromaDB Python project. This vulnerability allows an authenticated user to perform actions across different tenants, databases, or collections without proper authorization. The provider incorrectly evaluates user permissions without verifying the specific scope (tenant, database, or collection) to which those permissions apply. This can lead to unauthorized data access or modification across different user environments.
Отчет
is a post-authentication authorization flaw in ChromaDB’s SimpleRBAC provider — it does not grant unauthenticated access and does not enable code execution. RH AI products bundle a vulnerable chromadb version but do not run the Chroma Python server with SimpleRBAC as the default product architecture (AutoRAG uses Milvus/pgvector; RHEL AI bootc uses chromadb as a library). Upstream 8.8 High assumes a multi-tenant Chroma deployment with SimpleRBAC enabled and network reachability; that configuration is not the supported RH default, so Moderate is appropriate for RHOAI and Low for RHEL AI bootc.
Меры по смягчению последствий
To mitigate this issue, restrict network access to the ChromaDB instance to only trusted clients and services. Implement firewall rules to limit inbound connections to the ChromaDB port from authorized sources. If strict multi-tenant isolation is critical, consider deploying ChromaDB in a single-tenant configuration or exploring alternative authorization mechanisms if available, until a fix for the SimpleRBACAuthorizationProvider is deployed.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux AI (RHEL AI) 3 | rhelai3/bootc-cuda-rhel9 | Will not fix | ||
| Red Hat Enterprise Linux AI (RHEL AI) 3 | rhelai3/bootc-gaudi-rhel9 | Will not fix | ||
| Red Hat Enterprise Linux AI (RHEL AI) 3 | rhelai3/bootc-rocm-rhel9 | Will not fix | ||
| Red Hat Enterprise Linux AI (RHEL AI) 3 | rhelai3/disk-image-cuda-rhel9 | Will not fix | ||
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-autorag-rhel9 | Affected |
Показывать по
Дополнительная информация
Статус:
6.8 Medium
CVSS3
Связанные уязвимости
The SimpleRBACAuthorizationProvider authorization provider in versions 0.5.0 or later of the ChromaDB Python project evaluates whether a user holds a given permission but never checks which tenant, database, or collection that permission applies to allowing users to perform cross tenant actions.
The SimpleRBACAuthorizationProvider authorization provider in versions 0.5.0 or later of the ChromaDB Python project evaluates whether a user holds a given permission but never checks which tenant, database, or collection that permission applies to allowing users to perform cross tenant actions.
6.8 Medium
CVSS3