Impact
The gorch service template used by the trustyai-service-operator exposes its orchestrator and detector metrics ports without proper authentication even when the overall service has authentication enabled. This flaw, a Missing Authentication issue (CWE‑306), allows any pod on the OpenShift AI cluster network to reach the unproxied metrics endpoints, bypassing the kube-rbac-proxy and its authentication checks. The consequence is that an adversary can read detailed metrics that may reveal internal system state, operational parameters, or other sensitive information that could aid further attacks.
Affected Systems
Red Hat OpenShift AI installations that contain the trustyai-service-operator are affected. No specific version information is supplied, suggesting that the issue may exist across all current releases until addressed by a patch.
Risk and Exploitability
The CVSS score of 6.3 reflects moderate severity, while the EPSS score of < 1 % indicates that exploitation is unlikely but not impossible. The vulnerability is not listed in the CISA KEV catalog. Attackers can exploit the flaw by establishing an internal connection from any pod within the cluster to the exposed metrics ports, thereby bypassing the intended authentication controls. The weakness is a classic Missing Authentication issue (CWE‑306).
OpenCVE Enrichment