Bug 2216588 (CVE-2023-3361)

Summary: CVE-2023-3361 odh-dashboard: s3 credentials included when exporting elyra notebook
Product: [Other] Security Response Reporter: Anten Skrabec <askrabec>
Component: vulnerabilityAssignee: Nobody <nobody>
Status: NEW --- QA Contact:
Severity: high Docs Contact:
Priority: high    
Version: unspecifiedCC: jkoehler
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: odh-dashboard 1.28.1 Doc Type: ---
Doc Text:
A flaw was found in Red Hat OpenShift Data Science. When exporting a pipeline from the Elyra notebook pipeline editor as Python DSL or YAML, it reads S3 credentials from the cluster (ds pipeline server) and saves them in plain text in the generated output instead of an ID for a Kubernetes secret.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On:    
Bug Blocks: 2216589    

Description Anten Skrabec 2023-06-21 23:52:01 UTC
Exporting a pipeline from RHODS Elyra notebook pipeline editor as Python DSL or YAML reads S3 credentials from the cluster (ds pipeline server) and saves them in plain text in the generated output.