First published: Mon Feb 20 2023(Updated: )
A flaw was found in the Kubernetes service for notebooks in RHODS, where it does not prevent pods from other namespaces and applications from making requests to the Jupyter API. This flaw can lead to file content exposure and other issues.
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Redhat Openshift Data Science | >=1.22<1.22.1-3 | |
Redhat Enterprise Linux | =8.0 | |
All of | ||
Redhat Openshift Data Science | >=1.22<1.22.1-3 | |
Redhat Enterprise Linux | =8.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-0923 is a vulnerability found in the Kubernetes service for notebooks in RHODS, allowing pods from other namespaces and applications to make requests to the Jupyter API and potentially leading to file content exposure and other issues.
CVE-2023-0923 has a severity score of 9.8 (critical).
The Red Hat OpenShift Data Science version 1.22.1-3 is affected by CVE-2023-0923.
To fix CVE-2023-0923, update the affected Red Hat OpenShift Data Science version to a secure version.
You can find more information about CVE-2023-0923 in the Red Hat advisory at https://access.redhat.com/errata/RHSA-2023:0977.