Impact
A configuration flaw in operator‑sdk‑builder causes the containers‑policy.json file to default to insecureAcceptAnything for any container image registry that is not explicitly listed. With this default, the builder skips signature verification of images pulled from those registries, allowing attackers to inject untrusted or malicious containers. This flaw exposes the deployment process to compromised images that could execute arbitrary code or modify application behavior.
Affected Systems
The vulnerability applies to installations of operator‑sdk‑builder. No specific vendor or version information is provided, so all versions that use the default containers‑policy.json configuration are potentially affected.
Risk and Exploitability
The CVSS score is 4.2, indicating low severity, and the EPSS score is not available, while the vulnerability is not listed in CISA’s KEV catalog. The attack vector is likely network‑based, with an attacker providing a malicious image through an unlisted registry when the builder pulls container images. Although the risk is moderate, the consequence of executing malicious code in operator bundles makes early mitigation important.
OpenCVE Enrichment