CVE-2024-7557

Source
https://cve.org/CVERecord?id=CVE-2024-7557
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-7557.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-7557
Published
2024-08-08T21:33:14.505Z
Modified
2026-07-15T01:49:12.751516604Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
Odh-dashboard: odh-model-controller: cross-model authentication bypass in openshift ai
Details

A vulnerability was found in OpenShift AI that allows for authentication bypass and privilege escalation across models within the same namespace. When deploying AI models, the UI provides the option to protect models with authentication. However, credentials from one model can be used to access other models and APIs within the same namespace. The exposed ServiceAccount tokens, visible in the UI, can be utilized with oc --token={token} to exploit the elevated view privileges associated with the ServiceAccount, leading to unauthorized access to additional resources.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/7xxx/CVE-2024-7557.json",
    "cwe_ids": [
        "CWE-305"
    ],
    "cna_assigner": "redhat"
}
References

Affected packages

Git / github.com/opendatahub-io/odh-dashboard

Affected ranges

Type
GIT
Repo
https://github.com/opendatahub-io/odh-dashboard
Events
Database specific
{
    "extracted_events": [
        {
            "introduced": "2.8.*"
        },
        {
            "last_affected": "2.8.*"
        },
        {
            "introduced": "2.11"
        },
        {
            "last_affected": "2.11"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Affected versions

2.*
2.11
2.8.*
v2.*
v2.10.0
v2.11.0
v2.8.0
v2.9.0
v2.9.1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-7557.json"