Описание
A flaw was found in the TrustyAI Service (TAS) deployment. This vulnerability allows any pod on the cluster network to bypass authentication and directly access the TAS backend API. An attacker can exploit this to read, tamper with, or delete monitoring data and configurations, and inject arbitrary data into the service, potentially disrupting tenant operations.
Отчет
This vulnerability is rated as Important. The TrustyAI Service (TAS) in Red Hat OpenShift AI (RHOAI) deployments exposes its backend API without authentication to any pod on the cluster network, bypassing the intended kube-rbac-proxy security control. This allows unauthorized pods in other namespaces to access, tamper with, or delete another tenant's TAS monitoring data and configuration, leading to data integrity and availability concerns.
Дополнительная информация
Статус:
EPSS
8 High
CVSS3
Связанные уязвимости
A flaw was found in the TrustyAI Service (TAS) deployment. This vulnerability allows any pod on the cluster network to bypass authentication and directly access the TAS backend API. An attacker can exploit this to read, tamper with, or delete monitoring data and configurations, and inject arbitrary data into the service, potentially disrupting tenant operations.
A flaw was found in the TrustyAI Service (TAS) deployment. This vulnerability allows any pod on the cluster network to bypass authentication and directly access the TAS backend API. An attacker can exploit this to read, tamper with, or delete monitoring data and configurations, and inject arbitrary data into the service, potentially disrupting tenant operations.
EPSS
8 High
CVSS3