Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-569j-6vhh-8mc3

Опубликовано: 08 июл. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 6.3

Описание

A flaw was found in the TrustyAI Service Operator. When deploying services like gorch or NemoGuardrails, if a specific security setting is not enabled, these services can expose their communication channels without requiring users to prove their identity. This allows any other program within the cluster to access the AI guardrails and orchestrator without proper authorization. An attacker could exploit this to gain unauthorized access to sensitive information and potentially make limited changes to the AI models.

A flaw was found in the TrustyAI Service Operator. When deploying services like gorch or NemoGuardrails, if a specific security setting is not enabled, these services can expose their communication channels without requiring users to prove their identity. This allows any other program within the cluster to access the AI guardrails and orchestrator without proper authorization. An attacker could exploit this to gain unauthorized access to sensitive information and potentially make limited changes to the AI models.

EPSS

Процентиль: 7%
0.0017
Низкий

6.3 Medium

CVSS3

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 6.3
redhat
около 1 месяца назад

A flaw was found in the TrustyAI Service Operator. When deploying services like gorch or NemoGuardrails, if a specific security setting is not enabled, these services can expose their communication channels without requiring users to prove their identity. This allows any other program within the cluster to access the AI guardrails and orchestrator without proper authorization. An attacker could exploit this to gain unauthorized access to sensitive information and potentially make limited changes to the AI models.

CVSS3: 6.3
nvd
около 1 месяца назад

A flaw was found in the TrustyAI Service Operator. When deploying services like gorch or NemoGuardrails, if a specific security setting is not enabled, these services can expose their communication channels without requiring users to prove their identity. This allows any other program within the cluster to access the AI guardrails and orchestrator without proper authorization. An attacker could exploit this to gain unauthorized access to sensitive information and potentially make limited changes to the AI models.

EPSS

Процентиль: 7%
0.0017
Низкий

6.3 Medium

CVSS3

Дефекты

CWE-200