Redhat

Openshift Ai

37 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.24%
  • Veröffentlicht 10.08.2026 20:44:46
  • Zuletzt bearbeitet 19.08.2026 10:16:36

A flaw was found in the Feast operator. A malicious tenant could inject arbitrary code into their feature repository. This code would be executed by an automated process with elevated privileges, allowing the tenant to steal sensitive credentials. Th...

  • EPSS 0.58%
  • Veröffentlicht 10.08.2026 20:44:42
  • Zuletzt bearbeitet 14.08.2026 19:07:46

A flaw was found in Feast and feast-operator. The default configuration for both the Feast SDK and the feast-operator is "no_auth," meaning no security manager is installed. This default allows unauthenticated and unauthorized access to feature-serve...

  • EPSS 0.43%
  • Veröffentlicht 10.08.2026 20:44:33
  • Zuletzt bearbeitet 14.08.2026 19:07:46

A flaw was found in the Data Science Pipelines Operator (DSPO). A namespace editor can exploit a vulnerability in the spec.database.customExtraParams field, which allows for the injection of dangerous parameters into the MySQL Data Source Name (DSN) ...

  • EPSS 0.42%
  • Veröffentlicht 10.08.2026 20:44:28
  • Zuletzt bearbeitet 14.08.2026 19:07:46

A flaw was found in the Data Science Pipelines Operator (DSPO). The operator's ClusterRole, which defines its permissions, includes extensive privileges beyond what is necessary for its operation. These excessive permissions, such as the ability to e...

  • EPSS 0.3%
  • Veröffentlicht 10.08.2026 20:44:25
  • Zuletzt bearbeitet 14.08.2026 19:07:46

A flaw was found in the `odh-model-controller`. An authenticated user with permissions to create custom resources can exploit a vulnerability in the `loadSecret` function. This function improperly reads the Secret namespace from user-controlled input...

  • EPSS 0.24%
  • Veröffentlicht 10.08.2026 20:44:18
  • Zuletzt bearbeitet 14.08.2026 19:07:46

A flaw was found in the TrustyAI Service (TAS) deployment. This vulnerability allows any pod on the cluster network to bypass authentication and directly access the TAS backend API. An attacker can exploit this to read, tamper with, or delete monitor...

  • EPSS 0.37%
  • Veröffentlicht 10.08.2026 20:44:12
  • Zuletzt bearbeitet 14.08.2026 19:07:46

A flaw was found in the trustyai-service-operator's LMEvalJob controller. An authenticated user within the cluster can exploit this vulnerability by configuring a sidecar container to bypass existing security policies. This allows the user to enable ...

  • EPSS 0.39%
  • Veröffentlicht 10.08.2026 20:44:06
  • Zuletzt bearbeitet 14.08.2026 19:07:46

A flaw was found in the MaaS API. This vulnerability allows any pod within the cluster to bypass the Kuadrant AuthPolicy gateway by forging HTTP headers, specifically `X-MaaS-Username` and `X-MaaS-Group`, which are trusted verbatim. This lack of firs...

  • EPSS 0.31%
  • Veröffentlicht 10.08.2026 20:44:01
  • Zuletzt bearbeitet 14.08.2026 19:07:46

A flaw was found in the Red Hat OpenShift AI (RHOAI) MaaS Gateway. Improper configuration of the Gateway in a model-serving context allows a standard user with low privileges to intercept, read, log, and alter all MaaS model traffic. This includes se...

  • EPSS 0.27%
  • Veröffentlicht 23.07.2026 10:41:30
  • Zuletzt bearbeitet 11.08.2026 19:17:21

A flaw was found in odh-dashboard, the web console component of Red Hat OpenShift AI (RHOAI). Due to incorrect network binding, a malicious actor within the cluster can bypass authentication and impersonate any user by providing an arbitrary access t...