Red Hat OpenShift AI是美国Red Hat公司的一款混合云人工智能平台,为数据科学家和开发者提供跨混合云环境构建、开发、训练、部署、服务和监控机器学习(ML)模型及 AI 应用的全生命周期工具。 Red Hat OpenShift AI存在权限许可和访问控制问题漏洞,该漏洞源于maas-api和maas-controller服务账户被授予超出其操作需求的集群范围权限,攻击者通过远程代码执行漏洞或创建恶意Pod可提升至集群管理员权限或访问集群所有机密信息。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Red Hat | Red Hat OpenShift AI (RHOAI) | any |
affected |
any |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat OpenShift AI (RHOAI) | - |
cpe:/a:redhat:openshift_ai
|
|
| Red Hat | Red Hat OpenShift AI (RHOAI) | - |
cpe:/a:redhat:openshift_ai
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-66792 | 9.9 CRITICAL | Multicloud-operators-subscription: multicloud-operators-subscription: isclusteradmin() tru |
| CVE-2026-66795 | 9.1 CRITICAL | Managedcluster-import-controller: managedcluster-import-controller: csr auto-approver does |
| CVE-2026-71472 | 9.1 CRITICAL | Acm-search-v2-rhel9: search-v2-operator: shell-command and sql injection in postgresql-sta |
| CVE-2026-70495 | 8.8 HIGH | Search-v2-operator: search-v2-operator: cluster-wide impersonate on users/groups shared ac |
No comments yet