Impact
The vulnerability in Contrast allows an attacker with Kata agent API access to substitute container images without verifying image digests. The false allow_storage rule accepts images through the image_guest_pull driver, enabling an attacker to replace a trusted image with a malicious payload, undermining the integrity of the confidential container.
Affected Systems
Contrast versions 1.14.0 through 1.23.0 are affected. The product is Contrast from edgelesssys. Any deployment running a version prior to 1.23.1 is vulnerable.
Risk and Exploitability
The CVSS score is 7.6, indicating a high severity. The EPSS score is not available and the vulnerability is not listed in CISA's KEV catalog. The likely attack vector requires access to the Kata agent API, which is within Contrast's threat model (for example, a Kubernetes cluster administrator). By exploiting the policy generation flaw, an attacker could substitute the image with a malicious one that satisfies the remaining policy checks, thereby compromising container integrity.
OpenCVE Enrichment