The vendor explicitly identifies these products as affected by this CVE.
- rhoai/odh-workbench-jupyter-pytorch-llmcompressor-cuda-py312-rhel9 as a component of Red Hat OpenShift AI (RHOAI)
- Summary
- A flaw was found in mlflow/mlflow. When the `basic-auth` application is enabled, the FastAPI job endpoints are not protected by authentication or authorization. A remote attacker can exploit this by sending requests to these endpoints, bypassing security measures entirely. This can lead to unauthenticated remote code execution if allowed jobs perform privileged actions, or potentially result in job spam, denial of service (DoS), or data exposure.
- Remediation
- For Red Hat OpenShift AI 3.4.4 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this errata update: https://docs.redhat.com/en/documentation/red_hat_openshift_ai/
