Database/Control plane, storage & DevOps

Kubeflow (central dashboard, reflected cross-site scripting): Reflected XSS in the Kubeflow dashboard runs attacker
Impact
Reflected XSS in the Kubeflow dashboard runs attacker JavaScript in a logged-in user's browser under the Kubeflow origin. The attacker acts as that user against the Kubeflow API - which for an admin means creating notebooks and pipelines and reading other namespaces' resources.
Who can reach it
An authenticated Kubeflow user who follows an attacker-crafted link, so it needs both a valid session and a click.
What to do
Upgrade Kubeflow past the fixed dashboard release and redeploy the central dashboard. Add a Content-Security-Policy at the ingress in front of Kubeflow as a standing mitigation for this class.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.