Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-6193

Опубликовано: 20 июн. 2025
Источник: redhat
CVSS3: 5.9

Описание

A command injection vulnerability was discovered in the TrustyAI Explainability toolkit. Arbitrary commands placed in certain fields of a LMEValJob custom resource (CR) may be executed in the LMEvalJob pod's terminal. This issue can be exploited via a maliciously crafted LMEvalJob by a user with permissions to deploy a CR.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenShift AI (RHOAI)rhoai/odh-rhel8-operatorNot affected
Red Hat OpenShift AI (RHOAI)rhoai/odh-trustyai-service-operator-rhel8Affected
Red Hat OpenShift AI (RHOAI)rhoai/odh-trustyai-service-rhel8Not affected
Red Hat OpenShift AI (RHOAI)rhods/odh-rhel8-operatorNot affected
Red Hat OpenShift AI (RHOAI)rhods/odh-trustyai-service-operator-rhel8Affected
Red Hat OpenShift AI (RHOAI)rhods/odh-trustyai-service-rhel8Not affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-78
https://bugzilla.redhat.com/show_bug.cgi?id=2374032trustyai-explainability: command injection via LMEvalJob CR

5.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.9
nvd
6 месяцев назад

A command injection vulnerability was discovered in the TrustyAI Explainability toolkit. Arbitrary commands placed in certain fields of a LMEValJob custom resource (CR) may be executed in the LMEvalJob pod's terminal. This issue can be exploited via a maliciously crafted LMEvalJob by a user with permissions to deploy a CR.

CVSS3: 5.9
github
6 месяцев назад

A command injection vulnerability was discovered in the TrustyAI Explainability toolkit. Arbitrary commands placed in certain fields of a LMEValJob custom resource (CR) may be executed in the LMEvalJob pod's terminal. This issue can be exploited via a maliciously crafted LMEvalJob by a user with permissions to deploy a CR.

5.9 Medium

CVSS3