CVE Database
/

CVE-2023-0923

Back to search

CVE-2023-0923

Published: Sep 15, 2023

Modified: Aug 2, 2024

PUBLISHED

CVSS v3.1

8.8

HIGH

Description

A flaw was found in the Kubernetes service for notebooks in RHODS, where it does not prevent pods from other namespaces and applications from making requests to the Jupyter API. This flaw can lead to file content exposure and other issues.

VendorProductVersions

Red Hat

RHODS-1.22-RHEL-8

unaffected
v1.22.1-3 - < *

Weaknesses (CWE)

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Attack Vector

Adjacent

Attack Complexity

Low

Privileges Required

None

User Interaction

None

Scope

Unchanged

Confidentiality

High

Integrity

High

Availability

High

References

RHSA-2023:0977
vendor-advisory
x_refsource_REDHAT
RHBZ#2171870
issue-tracking
x_refsource_REDHAT

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now