TrustyAI Service Operator是TrustyAI组织的一款机器学习服务运营软件。 TrustyAI Service Operator存在授权问题漏洞,该漏洞源于身份验证绕过,允许集群网络上的任意pod直接访问后端API,攻击者可利用该漏洞读取、篡改或删除监控数据和配置,并注入任意数据,可能破坏租户操作。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Red Hat | Red Hat OpenShift AI 2.25 | 1785187119< * |
unaffected |
1787330073< * |
unaffected | ||
| Red Hat | Red Hat OpenShift AI 3.3 | 1785187521< * |
unaffected |
| Red Hat | Red Hat OpenShift AI 3.4 | 1784993206< * |
unaffected |
1786614608< * |
unaffected | ||
| Red Hat | Red Hat OpenShift AI 3.5 | 1786552271< * |
unaffected |
1786552250< * |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat OpenShift AI 2.25 | 1785187119 ~ * |
cpe:/a:redhat:openshift_ai:2.25::el9
|
|
| Red Hat | Red Hat OpenShift AI 2.25 | 1787330073 ~ * |
cpe:/a:redhat:openshift_ai:2.25::el9
|
|
| Red Hat | Red Hat OpenShift AI 3.3 | 1785187521 ~ * |
cpe:/a:redhat:openshift_ai:3.3::el9
|
|
| Red Hat | Red Hat OpenShift AI 3.4 | 1784993206 ~ * |
cpe:/a:redhat:openshift_ai:3.4::el9
|
|
| Red Hat | Red Hat OpenShift AI 3.4 | 1786614608 ~ * |
cpe:/a:redhat:openshift_ai:3.4::el9
|
|
| Red Hat | Red Hat OpenShift AI 3.5 | 1786552271 ~ * |
cpe:/a:redhat:openshift_ai:3.5::el9
|
|
| Red Hat | Red Hat OpenShift AI 3.5 | 1786552250 ~ * |
cpe:/a:redhat:openshift_ai:3.5::el9
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-18948 | 9.9 CRITICAL | Feast: feast: unsafe dill deserialization of registry-stored udfs — rce on feature server |
| CVE-2026-14450 | 9.9 CRITICAL | Maas-billing: maas api: privilege escalation via forged http headers due to missing authen |
| CVE-2026-18982 | 8.8 HIGH | Odh-training-operator-rhel9: rhoai fork aggregates training job create onto native edit/ad |
| CVE-2026-18950 | 8.8 HIGH | Odh-dashboard: odh-dashboard: confused-deputy privilege escalation via unchecked roleref i |
| CVE-2026-18949 | 8.8 HIGH | Odh-dashboard: odh-dashboard: clusterrole grants cluster-wide crud on secrets and rbac man |
| CVE-2026-18951 | 8.8 HIGH | Odh-training-operator-rhel9: [trainer v2 security] trn-02: rhoai overlay aggregates trainj |
| CVE-2026-18617 | 8.8 HIGH | Data-science-pipelines-operator: dspo: mysql dsn parameter injection via customextraparams |
| CVE-2026-18608 | 8.7 HIGH | Data-science-pipelines-operator: dspo: operator clusterrole grants pods/exec:*, kubeflow.o |
| CVE-2026-71576 | 8.5 HIGH | Multicluster-global-hub: multicluster-global-hub: manager trusts self-asserted evt.source( |
| CVE-2026-18947 | 8.5 HIGH | Feast: feast: authorization bypass in /materialize endpoints enables dos via unauthorized |
| CVE-2026-15467 | 8.1 HIGH | Trustyai-service-operator: trustyai-service-operator: lmevaljob sidecar containers bypass |
| CVE-2026-63622 | 7.8 HIGH | Libvirt: swtpm privilege escalation via symlink following |
| CVE-2026-18941 | 7.7 HIGH | Feast: feast-operator: feast: default authentication mode is no_auth — shared multi-tenant |
| CVE-2026-18621 | 7.6 HIGH | Data-sciences-pipeline: dsp: v1 argo template path accepts arbitrary workflow spec, bypass |
| CVE-2026-19387 | 7.6 HIGH | Gstreamer: gstreamer1-plugins-bad-free: gstreamer: heap out-of-bounds write in adpcmdec im |
| CVE-2026-18611 | 7.5 HIGH | Data-science-pipelines-operator: dspo: cryptographically weak secret generation (math/rand |
| CVE-2026-18618 | 7.5 HIGH | Ml-metdata: bundled grpc 1.46.3 (2022) with published http/2 dos cves — directly reachable |
| CVE-2026-19389 | 7.1 HIGH | Gstreamer: gstreamer1-plugins-ugly-free: gstreamer: integer overflow/underflow in asfdemux |
| CVE-2026-18620 | 7.1 HIGH | Data-sciences-pipeline: user-controlled serviceaccount for workflow pods without authoriza |
| CVE-2026-19278 | 6.8 MEDIUM | Stackrox: stackrox: privilege escalation via unanchored regular expressions in auth m2m ro |
Showing top 20 of 28 CVEs. View all on vendor page → →
No comments yet