Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-5483

Опубликовано: 10 апр. 2026
Источник: redhat
CVSS3: 8.5

Описание

A flaw was found in odh-dashboard in Red Hat Openshift AI. This vulnerability in the odh-dashboard component of Red Hat OpenShift AI (RHOAI) allows for the disclosure of Kubernetes Service Account tokens through a NodeJS endpoint. This could enable an attacker to gain unauthorized access to Kubernetes resources.

Отчет

A flaw in the odh-dashboard component of Red Hat OpenShift AI allows for the disclosure of Kubernetes Service Account tokens through a NodeJS endpoint. This vulnerability could enable an attacker to gain unauthorized access to Kubernetes resources within the OpenShift AI environment. The NIM serving API endpoint (/api/nim-serving/:nimResource) returns the full K8 client response including the dashboard's service account token. Requirements to exploit:

  • Authenticated access to the dashboard
  • The NIM account CR must exist on the cluster for 2.25+
  • The target secret must exist and if the secret referenced by the Account CR hasn't been created yet, the endpoint returns a 404 and no token is leaked

Меры по смягчению последствий

If applying the update is not immediately possible, the vulnerability can be mitigated by disabling or removing the NIM (NVIDIA Inference Microservice) integration from the Red Hat OpenShift AI (RHOAI) environment.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenShift AI (RHOAI)rhoai/odh-mod-arch-gen-ai-rhel9Not affected
Red Hat OpenShift AI (RHOAI)rhoai/odh-mod-arch-maas-rhel9Not affected
Red Hat OpenShift AI (RHOAI)rhoai/odh-mod-arch-model-registry-rhel9Not affected
Red Hat OpenShift AI 2.16rhoai/odh-dashboard-rhel8FixedRHSA-2026:739710.04.2026
Red Hat OpenShift AI 2.25rhoai/odh-dashboard-rhel9FixedRHSA-2026:739810.04.2026
Red Hat OpenShift AI 3.2rhoai/odh-dashboard-rhel9FixedRHSA-2026:740410.04.2026
Red Hat OpenShift AI 3.3rhoai/odh-dashboard-rhel9FixedRHSA-2026:740310.04.2026

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-201
https://bugzilla.redhat.com/show_bug.cgi?id=2454764odh-dashboard: ODH Dashboard Kubernetes Service Account Exposure

8.5 High

CVSS3

Связанные уязвимости

CVSS3: 8.5
nvd
4 месяца назад

A flaw was found in odh-dashboard in Red Hat Openshift AI. This vulnerability in the `odh-dashboard` component of Red Hat OpenShift AI (RHOAI) allows for the disclosure of Kubernetes Service Account tokens through a NodeJS endpoint. This could enable an attacker to gain unauthorized access to Kubernetes resources.

CVSS3: 8.5
github
4 месяца назад

A flaw was found in odh-dashboard in Red Hat Openshift AI. This vulnerability in the `odh-dashboard` component of Red Hat OpenShift AI (RHOAI) allows for the disclosure of Kubernetes Service Account tokens through a NodeJS endpoint. This could enable an attacker to gain unauthorized access to Kubernetes resources.

8.5 High

CVSS3