Impact
The vulnerability in Red Hat OpenShift AI arises from an incorrect aggregation of TrainJobs management permissions into the native Kubernetes edit ClusterRole. The flaw allows any user who has edit privileges in a namespace to create, modify, or delete TrainJobs. When combined with another known issue that permits arbitrary pod configurations, an attacker who is a namespace editor could potentially elevate privileges and achieve arbitrary code execution. The weakness is an instance of improper authorization with a CVSS score of 8.8, indicating a high severity.
Affected Systems
Red Hat OpenShift AI (RHOAI) overlay for the training operator is affected. The vulnerability applies to Red Hat OpenShift AI 3.3, 3.4, 3.5 on RHEL 9.
Risk and Exploitability
The CVSS score of 8.8 signals a high impact vulnerability, while the EPSS score of 0.00894 (<1%) indicates a low probability of exploitation. The flaw is not listed in CISA’s KEV catalog. The likely attack vector is within a namespace, exploiting Kubernetes RBAC for users with edit role privileges; a remote attacker with such permissions could exploit the design flaw to manipulate TrainJobs and potentially gain higher privileges.
OpenCVE Enrichment