Описание
A flaw was found in odh-dashboard in Red Hat Openshift AI. This vulnerability in the odh-dashboard component of Red Hat OpenShift AI (RHOAI) allows for the disclosure of Kubernetes Service Account tokens through a NodeJS endpoint. This could enable an attacker to gain unauthorized access to Kubernetes resources.
Отчет
A flaw in the odh-dashboard component of Red Hat OpenShift AI allows for the disclosure of Kubernetes Service Account tokens through a NodeJS endpoint. This vulnerability could enable an attacker to gain unauthorized access to Kubernetes resources within the OpenShift AI environment.
The NIM serving API endpoint (/api/nim-serving/:nimResource) returns the full K8 client response including the dashboard's service account token.
Requirements to exploit:
- Authenticated access to the dashboard
- The NIM account CR must exist on the cluster for 2.25+
- The target secret must exist and if the secret referenced by the Account CR hasn't been created yet, the endpoint returns a 404 and no token is leaked
Меры по смягчению последствий
If applying the update is not immediately possible, the vulnerability can be mitigated by disabling or removing the NIM (NVIDIA Inference Microservice) integration from the Red Hat OpenShift AI (RHOAI) environment.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-mod-arch-gen-ai-rhel9 | Not affected | ||
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-mod-arch-maas-rhel9 | Not affected | ||
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-mod-arch-model-registry-rhel9 | Not affected | ||
| Red Hat OpenShift AI 2.16 | rhoai/odh-dashboard-rhel8 | Fixed | RHSA-2026:7397 | 10.04.2026 |
| Red Hat OpenShift AI 2.25 | rhoai/odh-dashboard-rhel9 | Fixed | RHSA-2026:7398 | 10.04.2026 |
| Red Hat OpenShift AI 3.2 | rhoai/odh-dashboard-rhel9 | Fixed | RHSA-2026:7404 | 10.04.2026 |
| Red Hat OpenShift AI 3.3 | rhoai/odh-dashboard-rhel9 | Fixed | RHSA-2026:7403 | 10.04.2026 |
Показывать по
Дополнительная информация
Статус:
8.5 High
CVSS3
Связанные уязвимости
A flaw was found in odh-dashboard in Red Hat Openshift AI. This vulnerability in the `odh-dashboard` component of Red Hat OpenShift AI (RHOAI) allows for the disclosure of Kubernetes Service Account tokens through a NodeJS endpoint. This could enable an attacker to gain unauthorized access to Kubernetes resources.
A flaw was found in odh-dashboard in Red Hat Openshift AI. This vulnerability in the `odh-dashboard` component of Red Hat OpenShift AI (RHOAI) allows for the disclosure of Kubernetes Service Account tokens through a NodeJS endpoint. This could enable an attacker to gain unauthorized access to Kubernetes resources.
8.5 High
CVSS3