Impact
The TrustyAI Service Operator contains a flaw that enables unauthenticated access to the AI guardrails and orchestrator APIs when a specific security setting is disabled during deployment of services such as gorch or NemoGuardrails. Because a program running within the same OpenShift cluster can call these APIs, an attacker can read sensitive configuration and model data and possibly perform limited changes. This vulnerability corresponds to the weakness CWE‑200 for Information Exposure.
Affected Systems
Red Hat OpenShift AI (RHOAI) deployments that include the TrustyAI Service Operator are affected whenever the required security setting that protects the communication channels is not enabled. Services like gorch and NemoGuardrails are vulnerable under these conditions; no specific operator version is listed as affected, so all unpatched releases may be susceptible.
Risk and Exploitability
The CVSS score of 6.3 classifies the issue as moderate severity, and the EPSS score of less than 1% indicates a low probability of exploitation. The flaw is not listed in CISA KEV. The likely attack scenario involves an adversary who has already compromised a component inside the cluster; by leveraging the missing authentication they can reach the exposed APIs without privilege escalation. Based on the description, no special privileges beyond normal cluster component access are required for exploitation.
OpenCVE Enrichment