Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7rjm-5cpg-vwpq

Опубликовано: 10 авг. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 8

Описание

A flaw was found in the TrustyAI Service (TAS) deployment. This vulnerability allows any pod on the cluster network to bypass authentication and directly access the TAS backend API. An attacker can exploit this to read, tamper with, or delete monitoring data and configurations, and inject arbitrary data into the service, potentially disrupting tenant operations.

A flaw was found in the TrustyAI Service (TAS) deployment. This vulnerability allows any pod on the cluster network to bypass authentication and directly access the TAS backend API. An attacker can exploit this to read, tamper with, or delete monitoring data and configurations, and inject arbitrary data into the service, potentially disrupting tenant operations.

EPSS

Процентиль: 17%
0.00252
Низкий

8 High

CVSS3

Дефекты

CWE-306

Связанные уязвимости

CVSS3: 8
redhat
7 дней назад

A flaw was found in the TrustyAI Service (TAS) deployment. This vulnerability allows any pod on the cluster network to bypass authentication and directly access the TAS backend API. An attacker can exploit this to read, tamper with, or delete monitoring data and configurations, and inject arbitrary data into the service, potentially disrupting tenant operations.

CVSS3: 8
nvd
7 дней назад

A flaw was found in the TrustyAI Service (TAS) deployment. This vulnerability allows any pod on the cluster network to bypass authentication and directly access the TAS backend API. An attacker can exploit this to read, tamper with, or delete monitoring data and configurations, and inject arbitrary data into the service, potentially disrupting tenant operations.

EPSS

Процентиль: 17%
0.00252
Низкий

8 High

CVSS3

Дефекты

CWE-306