CyberRota Analysis
AI-GeneratedA vulnerability in the odh-dashboard component of Red Hat OpenShift AI allows authenticated users within a Kubernetes cluster to bypass authentication and impersonate any user by exploiting incorrect network binding. This could enable attackers to gain unauthorized access to the Kubernetes API, leading to potential arbitrary code execution, privilege escalation, or information disclosure. Organizations using Kubernetes and Red Hat OpenShift AI should prioritize remediation to mitigate the risk of exploitation.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
A flaw was found in odh-dashboard, the web console component of Red Hat OpenShift AI (RHOAI). Due to incorrect network binding, a malicious actor within the cluster can bypass authentication and impersonate any user by providing an arbitrary access token. This allows an attacker to gain unauthorized access to the Kubernetes API, potentially leading to arbitrary code execution, privilege escalation, or information disclosure.