Impact
A flaw in the Trustyai Service Operator’s LMEvalJob controller allows an authenticated cluster user to configure a sidecar container that bypasses existing security policies. By doing so, the attacker can enable and execute untrusted remote code, leading to arbitrary code execution inside the cluster. This vulnerability is a privilege escalation flaw (CWE‑266).
Affected Systems
The affected vendor is Red Hat, specifically the Red Hat OpenShift AI platform. The vulnerability impacts the trustyai‑service‑operator component. No specific affected version range is provided in the CVE data, so the patch status of the installed operator is unknown.
Risk and Exploitability
The CVSS score of 8.1 indicates a high severity vulnerability. The EPSS score is not available, so the current probability of exploitation is unclear, and the vulnerability is not listed in the CISA KEV catalog. Attacks require an authenticated user inside the cluster, suggesting the attack vector is local; however, once in place, the attacker can run arbitrary code throughout the cluster environment.
OpenCVE Enrichment