GPU VulnDB

Database/Control plane, storage & DevOps

Kubeflow (central dashboard, reflected cross-site scripting): Reflected XSS in the Kubeflow dashboard runs attacker

CVE-2023-6571Control plane, storage & DevOpscurated

Impact

Reflected XSS in the Kubeflow dashboard runs attacker JavaScript in a logged-in user's browser under the Kubeflow origin. The attacker acts as that user against the Kubeflow API - which for an admin means creating notebooks and pipelines and reading other namespaces' resources.

Who can reach it

An authenticated Kubeflow user who follows an attacker-crafted link, so it needs both a valid session and a click.

What to do

Upgrade Kubeflow past the fixed dashboard release and redeploy the central dashboard. Add a Content-Security-Policy at the ingress in front of Kubeflow as a standing mitigation for this class.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.