Impact
The issue is a flaw in the acm-operator-bundle build process where a script is downloaded and executed from a remote source without any verification of authenticity or integrity. The script has access to sensitive credentials, such as GitHub access tokens and registry passwords, that are used during the build. An attacker who can influence this remote source could insert malicious code, leading to unauthorized access to build resources and the compromise of the operator bundle.
Affected Systems
Red Hat Advanced Cluster Management for Kubernetes version 2 is impacted. Specific patch or sub‑version details are not provided in the data, so all releases of the 2.x line should be considered vulnerable until an official fix is released.
Risk and Exploitability
The CVSS score of 8.0 classifies this vulnerability as high severity. EPSS data is not available, making the current exploit probability uncertain, but the lack of a known KEV listing suggests no widespread exploitation has been observed yet. The likely attack vector involves an attacker who can modify the remote script source or otherwise influence the build environment, since the flaw requires the script to be executed in that context. This suggests that only users who have the ability to alter the build source or path can exploit the vulnerability, but once they do, the impact is significant.
OpenCVE Enrichment