Redhat

Openshift Ai

37 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.43%
  • Veröffentlicht 17.08.2026 13:39:18
  • Zuletzt bearbeitet 18.08.2026 15:04:46

A flaw was found in the maas-api and maas-controller ServiceAccounts within Red Hat OpenShift AI. These ServiceAccounts are granted cluster-wide permissions that exceed their operational requirements. An attacker who compromises the identity of these...

  • EPSS 0.31%
  • Veröffentlicht 10.08.2026 20:45:43
  • Zuletzt bearbeitet 14.08.2026 19:07:46

A flaw was found in Data Science Pipelines. A restricted user, or tenant, can exploit an improper authorization vulnerability in the setDefaultServiceAccount function. By specifying a more privileged ServiceAccount (SA) during a CreateRun request, an...

  • EPSS 0.52%
  • Veröffentlicht 10.08.2026 20:45:38
  • Zuletzt bearbeitet 14.08.2026 19:07:46

A flaw was found in ml-metadata. The statically-linked gRPC stack in ml-metadata is outdated, making it vulnerable to known HTTP/2 denial of service (DoS) issues. An in-cluster attacker, with network access to the MLMD pod, could exploit these vulner...

  • EPSS 0.38%
  • Veröffentlicht 10.08.2026 20:45:35
  • Zuletzt bearbeitet 14.08.2026 19:07:46

A flaw was found in the Data Science Pipelines Operator. This vulnerability allows an unauthenticated attacker to derive sensitive credentials, such as MariaDB root/user passwords and MinIO access/secret keys, if they can access the MinIO Route or Ma...

  • EPSS 0.48%
  • Veröffentlicht 10.08.2026 20:45:19
  • Zuletzt bearbeitet 14.08.2026 19:07:46

A flaw was found in the RHOAI training-operator. This vulnerability allows a user with standard edit or admin roles in any Kubernetes namespace to escalate their privileges. Through the creation of training jobs, an attacker can impersonate service a...

  • EPSS 0.57%
  • Veröffentlicht 10.08.2026 20:45:10
  • Zuletzt bearbeitet 14.08.2026 19:07:46

A flaw was found in the Red Hat OpenShift AI (RHOAI) overlay for the training operator. The RHOAI overlay incorrectly aggregates `trainjobs` management permissions into the native Kubernetes `edit ClusterRole`. This allows any user with `edit Cluster...

  • EPSS 0.4%
  • Veröffentlicht 10.08.2026 20:45:05
  • Zuletzt bearbeitet 19.08.2026 11:16:46

A flaw was found in odh-dashboard. An authenticated user of the dashboard can exploit a vulnerability related to how RoleBindings are created. The system does not properly validate the `roleRef` field, allowing a user to specify an arbitrary role, in...

  • EPSS 0.4%
  • Veröffentlicht 10.08.2026 20:45:00
  • Zuletzt bearbeitet 14.08.2026 19:07:46

A flaw was found in odh-dashboard. This vulnerability allows an attacker, who has compromised the dashboard's Service Account (SA) token, to exploit overly broad permissions granted to the SA. This enables the attacker to escalate their privileges to...

  • EPSS 0.69%
  • Veröffentlicht 10.08.2026 20:44:56
  • Zuletzt bearbeitet 19.08.2026 11:16:46

A flaw was found in Feast. The system improperly deserializes user-defined functions (UDFs) stored in its registry, which are serialized using the 'dill' library. This allows a remote attacker to store a malicious UDF, leading to unauthenticated arbi...

  • EPSS 0.49%
  • Veröffentlicht 10.08.2026 20:44:51
  • Zuletzt bearbeitet 19.08.2026 11:16:46

A flaw was found in Feast. An authorization bypass vulnerability exists in the /materialize and /materialize-incremental endpoints. By sending a specially crafted request that omits the feature_views field, an attacker can bypass intended permission ...