Impact
A flaw in the odh-model-controller allows an authenticated user with permissions to create custom resources to exploit the loadSecret function. The function reads the Secret namespace from user-controlled input without validation, enabling the reader to access secrets stored in other namespaces, such as API keys and cloud credentials. This results in information disclosure consistent with the Confused Deputy weakness (CWE‑441).
Affected Systems
The vulnerability affects Red Hat OpenShift AI (RHOAI) via the odh-model-controller component. All versions of RHOAI that include this controller are potentially affected; no specific version range is listed in the CNA data.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity. PEFS information is not available and the vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be an authenticated cluster user who has rights to create custom resources. No external attack is required; the attacker must already be authenticated within the cluster. Once the necessary permissions are obtained, the attacker can read sensitive data across namespaces, which can compromise confidentiality of cloud credentials and other secrets.
OpenCVE Enrichment