Impact
The Data Science Pipelines Operator generates MariaDB root passwords and MinIO access/secret keys using a weak pseudo-random number generator from math/rand, making the credentials predictable. An attacker who can access the MinIO Route or MariaDB Service, even without authentication, can derive these secrets and thereby gain unauthorized access to all pipeline artifacts and metadata, leading to significant information disclosure.
Affected Systems
The vulnerability affects Red Hat OpenShift AI, specifically the Data Science Pipelines Operator. Version information is not provided in the data.
Risk and Exploitability
The CVSS score of 7.5 indicates a moderate-to-high risk, and the exploit probability score is not available. The flaw is not listed in CISA KEV. An unauthenticated attacker who reaches the exposed MinIO Route or MariaDB Service can easily predict the weakly generated credentials, resulting in convenient exploitation if network exposure persists.
OpenCVE Enrichment