A command injection vulnerability was discovered in the TrustyAI Explainability toolkit. Arbitrary commands placed in certain fields of a LMEValJob custom resource (CR) may be executed in the LMEvalJob pod's terminal. This issue can be exploited via a maliciously crafted LMEvalJob by a user with permissions to deploy a CR.
Exploitability
AV:NAC:LPR:HUI:RScope
S:CImpact
C:LI:LA:L5.9/CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:LInjection