A flaw was found in Red Hat OpenShift Data Science. When exporting a pipeline from the Elyra notebook pipeline editor as Python DSL or YAML, it reads S3 credentials from the cluster (ds pipeline server) and saves them in plain text in the generated output instead of an ID for a Kubernetes secret.
References
Link | Resource |
---|---|
https://access.redhat.com/security/cve/CVE-2023-3361 | Third Party Advisory |
https://bugzilla.redhat.com/show_bug.cgi?id=2216588 | Issue Tracking Third Party Advisory |
https://github.com/opendatahub-io/odh-dashboard/issues/1415 | Issue Tracking |
https://access.redhat.com/security/cve/CVE-2023-3361 | Third Party Advisory |
https://bugzilla.redhat.com/show_bug.cgi?id=2216588 | Issue Tracking Third Party Advisory |
https://github.com/opendatahub-io/odh-dashboard/issues/1415 | Issue Tracking |
Configurations
History
21 Nov 2024, 08:17
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.7 |
References | () https://access.redhat.com/security/cve/CVE-2023-3361 - Third Party Advisory | |
References | () https://bugzilla.redhat.com/show_bug.cgi?id=2216588 - Issue Tracking, Third Party Advisory | |
References | () https://github.com/opendatahub-io/odh-dashboard/issues/1415 - Issue Tracking |
05 Oct 2023, 17:01
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.5 |
CWE | CWE-319 | |
CPE | cpe:2.3:a:redhat:openshift_data_science:-:*:*:*:*:*:*:* cpe:2.3:a:opendatahub:open_data_hub_dashboard:*:*:*:*:*:*:*:* |
|
First Time |
Redhat openshift Data Science
Redhat Opendatahub open Data Hub Dashboard Opendatahub |
|
References | (MISC) https://access.redhat.com/security/cve/CVE-2023-3361 - Third Party Advisory | |
References | (MISC) https://bugzilla.redhat.com/show_bug.cgi?id=2216588 - Issue Tracking, Third Party Advisory | |
References | (MISC) https://github.com/opendatahub-io/odh-dashboard/issues/1415 - Issue Tracking |
04 Oct 2023, 12:56
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-10-04 12:15
Updated : 2024-11-21 08:17
NVD link : CVE-2023-3361
Mitre link : CVE-2023-3361
CVE.ORG link : CVE-2023-3361
JSON object : View
Products Affected
opendatahub
- open_data_hub_dashboard
redhat
- openshift_data_science