Impact
A flaw was discovered in the tool used to build operator bundles: operator-sdk-builder lacks mechanisms for automatically updating its git submodules, base images in the Containerfile, and Tekton bundle references. This omission means that when a build is performed, any dependency that has become stale or vulnerable can be pulled in without the build operator being aware, thereby allowing a known insecure component to become part of the final operator bundle.
Affected Systems
All installations of operator-sdk-builder that are used to produce operator bundles and rely on external git submodules, a Containerfile, or Tekton bundle references are affected. The issue applies regardless of the target deployment environment or the cloud platform in which the operator will run.
Risk and Exploitability
The CVSS score of 2.6 indicates low severity. Based on the description, the likely attack vector is a supply‑chain compromise of a submodule, base image, or bundle reference, or a deliberate omission by a build operator. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, implying a low probability of automated exploitation. However, an attacker who succeeds in injecting a vulnerable component or who relies on an unpatched dependency could create an operator bundle that contains known security weaknesses, potentially leading to downstream exploitation once the operator is deployed.
OpenCVE Enrichment