CyberRota Analysis
AI-GeneratedThe gorch service template within the trustyai-service-operator has a vulnerability that exposes unproxied orchestrator and detector metrics ports, even with authentication enabled. This flaw allows any pod on the cluster network to access these metrics directly, circumventing kube-rbac-proxy's authentication, potentially leading to unauthorized access to sensitive metrics. Organizations using the trustyai-service-operator should prioritize addressing this vulnerability to safeguard their cluster's security.
Original NVD Description
A flaw was found in the gorch service template, which is part of the trustyai-service-operator. Even when authentication is enabled, the gorch service exposes unproxied orchestrator and detector metrics ports. This allows any pod on the cluster network to directly access these ports, bypassing the kube-rbac-proxy and its authentication mechanisms. This could lead to unauthorized access to the orchestrator and detector metrics.