Red Hat OpenShift AI是美国Red Hat公司的一款混合云人工智能平台,为数据科学家和开发者提供跨混合云环境构建、开发、训练、部署、服务和监控机器学习(ML)模型及 AI 应用的全生命周期工具。 Red Hat OpenShift AI存在安全漏洞,该漏洞源于系统未正确验证RoleBindings创建时的roleRef字段,允许用户指定任意角色(包括高权限的cluster-admin),可能导致权限提升,攻击者可在其命名空间内获得未授权的提升访问权限并可能持久控制系统。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Red Hat | Red Hat OpenShift AI (RHOAI) | any |
unaffected |
any |
unaffected | ||
any |
unaffected | ||
any |
unaffected | ||
any |
unaffected | ||
any |
unaffected | ||
any |
unaffected | ||
| Red Hat | Red Hat OpenShift AI 2.25 | 1785940823< * |
unaffected |
| Red Hat | Red Hat OpenShift AI 3.3 | 1786109683< * |
unaffected |
| Red Hat | Red Hat OpenShift AI 3.4 | 1786109665< * |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat OpenShift AI 2.25 | 1785940823 ~ * |
cpe:/a:redhat:openshift_ai:2.25::el9
|
|
| Red Hat | Red Hat OpenShift AI 3.3 | 1786109683 ~ * |
cpe:/a:redhat:openshift_ai:3.3::el9
|
|
| Red Hat | Red Hat OpenShift AI 3.4 | 1786109665 ~ * |
cpe:/a:redhat:openshift_ai:3.4::el9
|
|
| Red Hat | Red Hat OpenShift AI (RHOAI) | - |
cpe:/a:redhat:openshift_ai
|
|
| Red Hat | Red Hat OpenShift AI (RHOAI) | - |
cpe:/a:redhat:openshift_ai
|
|
| Red Hat | Red Hat OpenShift AI (RHOAI) | - |
cpe:/a:redhat:openshift_ai
|
|
| Red Hat | Red Hat OpenShift AI (RHOAI) | - |
cpe:/a:redhat:openshift_ai
|
|
| Red Hat | Red Hat OpenShift AI (RHOAI) | - |
cpe:/a:redhat:openshift_ai
|
|
| Red Hat | Red Hat OpenShift AI (RHOAI) | - |
cpe:/a:redhat:openshift_ai
|
|
| Red Hat | Red Hat OpenShift AI (RHOAI) | - |
cpe:/a:redhat:openshift_ai
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-18948 | 9.9 CRITICAL | Feast: feast: unsafe dill deserialization of registry-stored udfs — rce on feature server |
| CVE-2026-14450 | 9.9 CRITICAL | Maas-billing: maas api: privilege escalation via forged http headers due to missing authen |
| CVE-2026-18949 | 8.8 HIGH | Odh-dashboard: odh-dashboard: clusterrole grants cluster-wide crud on secrets and rbac man |
| CVE-2026-18951 | 8.8 HIGH | Odh-training-operator-rhel9: [trainer v2 security] trn-02: rhoai overlay aggregates trainj |
| CVE-2026-18617 | 8.8 HIGH | Data-science-pipelines-operator: dspo: mysql dsn parameter injection via customextraparams |
| CVE-2026-18982 | 8.8 HIGH | Odh-training-operator-rhel9: rhoai fork aggregates training job create onto native edit/ad |
| CVE-2026-18608 | 8.7 HIGH | Data-science-pipelines-operator: dspo: operator clusterrole grants pods/exec:*, kubeflow.o |
| CVE-2026-18947 | 8.5 HIGH | Feast: feast: authorization bypass in /materialize endpoints enables dos via unauthorized |
| CVE-2026-71576 | 8.5 HIGH | Multicluster-global-hub: multicluster-global-hub: manager trusts self-asserted evt.source( |
| CVE-2026-15467 | 8.1 HIGH | Trustyai-service-operator: trustyai-service-operator: lmevaljob sidecar containers bypass |
| CVE-2026-15581 | 8.0 HIGH | Trustyai-service-operator: trustyai-service-operator: tas internal service bypasses kube-r |
| CVE-2026-63622 | 7.8 HIGH | Libvirt: swtpm privilege escalation via symlink following |
| CVE-2026-18941 | 7.7 HIGH | Feast: feast-operator: feast: default authentication mode is no_auth — shared multi-tenant |
| CVE-2026-18621 | 7.6 HIGH | Data-sciences-pipeline: dsp: v1 argo template path accepts arbitrary workflow spec, bypass |
| CVE-2026-19387 | 7.6 HIGH | Gstreamer: gstreamer1-plugins-bad-free: gstreamer: heap out-of-bounds write in adpcmdec im |
| CVE-2026-18611 | 7.5 HIGH | Data-science-pipelines-operator: dspo: cryptographically weak secret generation (math/rand |
| CVE-2026-18618 | 7.5 HIGH | Ml-metdata: bundled grpc 1.46.3 (2022) with published http/2 dos cves — directly reachable |
| CVE-2026-19389 | 7.1 HIGH | Gstreamer: gstreamer1-plugins-ugly-free: gstreamer: integer overflow/underflow in asfdemux |
| CVE-2026-18620 | 7.1 HIGH | Data-sciences-pipeline: user-controlled serviceaccount for workflow pods without authoriza |
| CVE-2026-19278 | 6.8 MEDIUM | Stackrox: stackrox: privilege escalation via unanchored regular expressions in auth m2m ro |
Showing top 20 of 28 CVEs. View all on vendor page → →
No comments yet