Impact
The Data Science Pipelines Operator assigns a ClusterRole with overly broad permissions, including pods/exec, full CRUD on kubeflow.org resources, and unrestricted API groups for deployments and services. This configuration allows an attacker who gains access to the DSPO pod to execute commands inside any pod, create, modify, or delete cluster‑wide roles and bindings, and otherwise hijack control of the Kubernetes cluster. The flaw is a classic privilege‑escalation vulnerability (CWE‑250).
Affected Systems
Red Hat OpenShift AI (RHOAI) deployments that include the Data Science Pipelines Operator are affected. No specific version range is listed in the CNA data, so all current DSPO releases should be considered vulnerable until an official fix is released.
Risk and Exploitability
The CVSS score of 8.7 indicates high severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, but the impact of configuration is still significant. Exploitation would require local access to the DSPO pod or a successful compromise of the pod’s credentials. Once compromised, an attacker can leverage the role to perform cluster‑wide operations, effectively gaining administrative control. The lack of an official patch means the risk persists until the ClusterRole is manually tightened or a vendor‑released fix is applied.
OpenCVE Enrichment