CVE-2023-0923
Published on: Not Yet Published
Last Modified on: 09/20/2023 08:40:00 PM UTC
Certain versions of Enterprise Linux from Redhat contain the following vulnerability:
A flaw was found in the Kubernetes service for notebooks in RHODS, where it does not prevent pods from other namespaces and applications from making requests to the Jupyter API. This flaw can lead to file content exposure and other issues.
- CVE-2023-0923 has been assigned by
seca[email protected] to track the vulnerability - currently rated as CRITICAL severity.
- Affected Vendor/Software:
Red Hat - RHODS-1.22-RHEL-8 version not down converted
CVSS3 Score: 9.8 - CRITICAL
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
NETWORK | LOW | NONE | NONE |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | HIGH | HIGH | HIGH |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
Red Hat | access.redhat.com text/html |
![]() |
cve-details | access.redhat.com text/html |
![]() |
2171870 – (CVE-2023-0923) CVE-2023-0923 odh-notebook-controller-container: Missing authorization allows for file contents disclosure | bugzilla.redhat.com text/html |
![]() |
There are currently no QIDs associated with this CVE
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Operating System | Redhat | Enterprise Linux | 8.0 | All | All | All |
Application | Redhat | Openshift Data Science | All | All | All | All |
- cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*:
- cpe:2.3:a:redhat:openshift_data_science:*:*:*:*:*:*:*:*:
No vendor comments have been submitted for this CVE
Social Mentions
Source | Title | Posted (UTC) |
---|