Impact
A flaw in the Trustyai-service-operator allows any pod within the cluster network to bypass the kube-rbac-proxy and directly reach the underlying Quarkus API. This exposes a broad API surface for unauthorized actors, who can read, modify or delete monitoring data and configuration, and may inject malicious content that can disrupt tenant operations. The flaw is a manifestation of the authentication bypass weakness detailed by CWE-306.
Affected Systems
Red Hat OpenShift AI (RHOAI) deployments that use the Trustyai-service-operator, which includes the TrustyAI Service backend. No specific version range is listed, so all currently deployed instances are potentially vulnerable unless they have the fix applied.
Risk and Exploitability
The CVSS score of 8 indicates a high severity level. The EPSS score is not available, so the current probability of exploitation is unknown. The vulnerability is not listed in the CISA KEV catalog, suggesting no known widespread exploitation yet. Attackers only need network access to a pod in the cluster, which is a common capability for any workload running in OpenShift. If a malicious pod is introduced, the attacker can easily reach the TAS API, making the vulnerability straightforward to exploit under typical cluster conditions.
OpenCVE Enrichment