Impact
The vulnerability originates from recursive copying of build context directories into container images within IBM Concert Software versions 1.0.0 through 3.0.0. A local attacker able to run code in the build environment can read files that were not intended to be included in the image, thereby compromising confidential data. This weakness is classified as CWE‑552, which reflects insufficient protection of internal information. The flaw does not enable remote code execution or denial of service, but it fully exposes privileged data to anyone gaining local execution rights.
Affected Systems
IBM Concert Software versions 1.0.0 to 3.0.0 are affected. The affected product includes IBM:Concert container orchestration and Docker build capabilities. The vendor recommends upgrading to IBM Concert Software 3.0.1.1 to fix the issue; all prior releases remain vulnerable.
Risk and Exploitability
The CVSS score of 6.2 indicates a medium severity. EPSS is unavailable, so the exploit probability is unknown. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires a local attacker with sufficient privileges within the build environment, making it less likely to be leveraged by remote attackers but still a significant risk for internal threats or compromised accounts.
OpenCVE Enrichment