A flaw was found in Red Hat OpenShift Data Science. When exporting a pipeline from the Elyra notebook pipeline editor as Python DSL or YAML, it reads S3 credentials from the cluster (ds pipeline server) and saves them in plain text in the generated output instead of an ID for a Kubernetes secret.
References
Link | Resource |
---|---|
https://access.redhat.com/security/cve/CVE-2023-3361 | Third Party Advisory |
https://bugzilla.redhat.com/show_bug.cgi?id=2216588 | Issue Tracking Third Party Advisory |
https://github.com/opendatahub-io/odh-dashboard/issues/1415 | Issue Tracking |
Configurations
History
No history.
Information
Published : 2023-10-04 12:15
Updated : 2023-11-07 04:18
NVD link : CVE-2023-3361
Mitre link : CVE-2023-3361
CVE.ORG link : CVE-2023-3361
JSON object : View
Products Affected
redhat
- openshift_data_science
opendatahub
- open_data_hub_dashboard