NVIDIA AIStore - AuthN: An unauthenticated user extracts information from the AIStore authentication component
CVE-2025-33185NVIDIA / GPU stackcurated
Impact
An unauthenticated user extracts information from the AIStore authentication component. AIStore fronts training datasets, so what leaks here is metadata about your data estate.
Who can reach it
Network, unauthenticated, no user interaction. Anyone who can reach the AuthN endpoint.
What to do
Upgrade AIStore per bulletin 5724 and roll the AuthN pods. Cost: rolling restart of the storage control plane; data path is unaffected.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.