{
  "threat_severity" : "Moderate",
  "public_date" : "2025-10-28T09:00:00Z",
  "bugzilla" : {
    "description" : "openshift-ai: Trusty AI Grants All Authenticated users to list pods in any namespace",
    "id" : "2405966",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=2405966"
  },
  "cvss3" : {
    "cvss3_base_score" : "5.0",
    "cvss3_scoring_vector" : "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N",
    "status" : "verified"
  },
  "cwe" : "CWE-266",
  "details" : [ "A flaw was found in Red Hat Openshift AI Service. The TrustyAI component is granting all service accounts and users on a cluster permissions to  get, list, watch any pod in any namespace on the cluster.\nTrustyAI is creating a role `trustyai-service-operator-lmeval-user-role` and a CRB `trustyai-service-operator-default-lmeval-user-rolebinding` which is being applied to `system:authenticated` making it so that every single user or service account can get a list of pods running in any namespace on the cluster \nAdditionally users can access all `persistentvolumeclaims` and `lmevaljobs`", "A flaw was found in Red Hat Openshift AI Service. The TrustyAI component is granting all service accounts and users on a cluster permissions to  get, list, watch any pod in any namespace on the cluster.\nTrustyAI is creating a role `trustyai-service-operator-lmeval-user-role` and a CRB `trustyai-service-operator-default-lmeval-user-rolebinding` which is being applied to `system:authenticated` making it so that every single user or service account can get a list of pods running in any namespace on the cluster \nAdditionally users can access all `persistentvolumeclaims` and `lmevaljobs`" ],
  "statement" : "Red Hat considers this as Moderate as the information available the limitation is limited to PVC and Pods.",
  "affected_release" : [ {
    "product_name" : "Red Hat OpenShift AI 2.25",
    "release_date" : "2026-04-23T00:00:00Z",
    "advisory" : "RHSA-2026:10184",
    "cpe" : "cpe:/a:redhat:openshift_ai:2.25::el9",
    "package" : "rhoai/odh-ta-lmes-driver-rhel9:sha256:6503aa2b0c29d01b947b6fde383850d03dcb2b9f9d70cf417b9e90d5e99d1740"
  }, {
    "product_name" : "Red Hat OpenShift AI 3",
    "release_date" : "2025-11-12T00:00:00Z",
    "advisory" : "RHSA-2025:21117",
    "cpe" : "cpe:/a:redhat:openshift_ai:3.0::el9",
    "package" : "rhoai/odh-trustyai-service-operator-rhel9:sha256:2015d93a8f499c4b3706fb1b1323db2e455154cb20219ceef82b79894239a51b"
  } ],
  "package_state" : [ {
    "product_name" : "Red Hat OpenShift AI (RHOAI)",
    "fix_state" : "Affected",
    "package_name" : "rhoai/odh-trustyai-service-operator-rhel8",
    "cpe" : "cpe:/a:redhat:openshift_ai"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2025-12103\nhttps://nvd.nist.gov/vuln/detail/CVE-2025-12103" ],
  "name" : "CVE-2025-12103",
  "mitigation" : {
    "value" : "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
    "lang" : "en:us"
  },
  "csaw" : false
}