在 Red Hat OpenShift AI 的 odh-dashboard 中发现了一个缺陷。其后端对前端(BFF)的 API 路由 使用 dashboard 的服务账户(Service Account)读取 Kubernetes Secret,并返回完整的 Secret 对象(包括 字段),但未进行任何授权检查。任何已认证的 dashboard 用户均可获取集群中的 NVIDIA NGC API 密钥 Secret( )以及 NIM 镜像拉取密钥( )。虽然对上述 NIM 凭据的创建和删除操作受管理员权限控制,
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat OpenShift AI (RHOAI) | - |
cpe:/a:redhat:openshift_ai
|
|
| Red Hat | Red Hat OpenShift AI (RHOAI) | - |
cpe:/a:redhat:openshift_ai
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet