Impact
The flaw in operator-sdk-builder permits referencing its base container image with a mutable tag rather than a stable sha256 digest. This practice allows the underlying image to change between builds, which could silently introduce vulnerabilities or malicious code into the build process. The impact is a supply‑chain integrity compromise, exposing builds to unintended code injection or vulnerability escalation.
Affected Systems
operator-sdk-builder is affected. No specific vendor or product version details were provided in the audit. Users should verify whether their installed operator-sdk-builder instance resolves base images via mutable tags.
Risk and Exploitability
The vulnerability received a CVSS score of 2.6, indicating low severity, and is not listed in CISA's KEV catalog. No EPSS score is available, but the inherent risk lies in the potential for supply‑chain tampering rather than direct exploitation. Attackers likely need to influence the container registry or supply a malicious image under a mutable tag to affect the build, a condition that could arise if registry access is not restricted or provenance checks are absent.
OpenCVE Enrichment