Impact
The flaw in mce‑operator‑bundle allows a malicious actor with write access to the stolostron/release repository to inject arbitrary code into the bundle generation process. Because the build process fetches and executes scripts from this mutable source without performing integrity checks, the injected code runs during build time, resulting in compromised binaries that can be distributed to downstream consumers. This weakness is classified as CWE‑829 and CWE‑1357.
Affected Systems
Red Hat Multicluster Engine for Kubernetes versions 2.6, 2.8, 2.9, 2.10, 2.11, and 2.17 are affected, as the vulnerability exists in the mce‑operator‑bundle component used by these product releases. The impact arises from the build process of the operator bundle, which sources its logic from the stolostron/release repository. Any deployment that relies on the current operator bundle built from the master branch during the time the flaw existed is potentially impacted.
Risk and Exploitability
The CVSS score of 7.7 indicates high severity, while the EPSS score of less than 1% indicates a very low but non‑zero exploitation probability. The vulnerability is not listed in CISA’s KEV catalog. The attack path requires write access to the remote repository; therefore, the immediate risk is limited to environments where repository permissions cannot be strictly controlled. Once malicious code is injected, the resulting artifacts can propagate to all downstream users, potentially enabling privilege escalation, persistence, or further supply‑chain attacks.
OpenCVE Enrichment