CVE-2023-0923

A flaw was found in the Kubernetes service for notebooks in RHODS, where it does not prevent pods from other namespaces and applications from making requests to the Jupyter API. This flaw can lead to file content exposure and other issues.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:redhat:openshift_data_science:*:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*

History

21 Nov 2024, 07:38

Type Values Removed Values Added
References () https://access.redhat.com/errata/RHSA-2023:0977 - Vendor Advisory () https://access.redhat.com/errata/RHSA-2023:0977 - Vendor Advisory
References () https://access.redhat.com/security/cve/CVE-2023-0923 - Vendor Advisory () https://access.redhat.com/security/cve/CVE-2023-0923 - Vendor Advisory
References () https://bugzilla.redhat.com/show_bug.cgi?id=2171870 - Issue Tracking, Vendor Advisory () https://bugzilla.redhat.com/show_bug.cgi?id=2171870 - Issue Tracking, Vendor Advisory
CVSS v2 : unknown
v3 : 9.8
v2 : unknown
v3 : 8.8

20 Sep 2023, 20:40

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
First Time Redhat openshift Data Science
Redhat
Redhat enterprise Linux
CWE CWE-862
CPE cpe:2.3:a:redhat:openshift_data_science:*:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
References (MISC) https://access.redhat.com/errata/RHSA-2023:0977 - (MISC) https://access.redhat.com/errata/RHSA-2023:0977 - Vendor Advisory
References (MISC) https://access.redhat.com/security/cve/CVE-2023-0923 - (MISC) https://access.redhat.com/security/cve/CVE-2023-0923 - Vendor Advisory
References (MISC) https://bugzilla.redhat.com/show_bug.cgi?id=2171870 - (MISC) https://bugzilla.redhat.com/show_bug.cgi?id=2171870 - Issue Tracking, Vendor Advisory

17 Sep 2023, 12:01

Type Values Removed Values Added
New CVE

Information

Published : 2023-09-15 21:15

Updated : 2024-11-21 07:38


NVD link : CVE-2023-0923

Mitre link : CVE-2023-0923

CVE.ORG link : CVE-2023-0923


JSON object : View

Products Affected

redhat

  • openshift_data_science
  • enterprise_linux
CWE
CWE-862

Missing Authorization