Data-sciences-pipeline: dsp: v1 argo template path accepts arbitrary workflow spec, bypassing all v2 security hardening
21Vexday Risk Score
Sem sinal de exploração. Nenhum artefato público de exploração conhecido até agora.
ssvc Trackcvss 7.6epss 0.4%
probabilidade de exploração
0.4%top 69% das CVEs
exploração observada
nãonenhuma fonte reporta
A flaw was found in Data Science Pipelines (DSP). An attacker with namespace editor privileges can bypass security hardening by submitting a malicious Argo Workflow through the V1 API path. This allows the API server to create pods with elevated privileges, acting as a 'confused deputy' on behalf of the attacker. Successful exploitation grants the attacker node-root access, enabling arbitrary code execution and full control over the underlying node.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L
Produtos afetados
Red Hat · Red Hat AI Inference ServerRed Hat · Red Hat OpenShift AI 2.25Red Hat · Red Hat OpenShift AI 3.3Red Hat · Red Hat OpenShift AI 3.4Referências
https://access.redhat.com/errata/RHSA-2026:53261https://access.redhat.com/errata/RHSA-2026:53262https://access.redhat.com/errata/RHSA-2026:53263https://access.redhat.com/errata/RHSA-2026:60520https://access.redhat.com/errata/RHSA-2026:65126https://access.redhat.com/security/cve/CVE-2026-18621https://bugzilla.redhat.com/show_bug.cgi?id=2510327