Trustyai-service-operator: trustyai-service-operator: tas internal service bypasses kube-rbac-proxy, exposing unauthenticated quarkus api cluster-wide
21Vexday Risk Score
Sem sinal de exploração. Nenhum artefato público de exploração conhecido até agora.
ssvc Trackcvss 8epss 0.3%
probabilidade de exploração
0.3%top 82% das CVEs
exploração observada
nãonenhuma fonte reporta
A flaw was found in the TrustyAI Service (TAS) deployment. This vulnerability allows any pod on the cluster network to bypass authentication and directly access the TAS backend API. An attacker can exploit this to read, tamper with, or delete monitoring data and configurations, and inject arbitrary data into the service, potentially disrupting tenant operations.
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Produtos afetados
Red Hat · Red Hat OpenShift AI 2.25Red Hat · Red Hat OpenShift AI 3.3Red Hat · Red Hat OpenShift AI 3.4Referências
https://access.redhat.com/errata/RHSA-2026:53261https://access.redhat.com/errata/RHSA-2026:53262https://access.redhat.com/errata/RHSA-2026:53263https://access.redhat.com/errata/RHSA-2026:60520https://access.redhat.com/errata/RHSA-2026:65126https://access.redhat.com/security/cve/CVE-2026-15581https://bugzilla.redhat.com/show_bug.cgi?id=2499637