Impact
A flaw in the operator-sdk-builder Containerfile leaves the final built image with a USER root directive that is never overridden. As a result, any process executed inside the image runs with full root privileges, expanding the attack surface and allowing a compromised container to perform unauthorized actions that could reach beyond the container boundaries.
Affected Systems
This issue affects operator images built with operator-sdk-builder when the default Containerfile configuration is used. No specific vendor or version list is provided, but any environment that generates operator images without explicitly changing the USER directive will inherit this root execution.
Risk and Exploitability
The CVSS score of 4.2 indicates moderate severity, and the EPSS score is currently unavailable. The vulnerability is not listed in the CISA KEV catalog. The flaw is classified as CWE-250. While the lack of a public EPSS score limits precise risk forecasting, the fact that the image runs as root by default creates a clear privilege escalation path. An attacker who can gain code execution inside the container, or who can influence the image content, may be able to perform elevated operations that could lead to host compromise if additional escape conditions are met.
OpenCVE Enrichment