Impact
Malware could be introduced into the software supply chain by using mutable floating tags for runtime base images. The build pipelines reference base images by name rather than by immutable SHA256 digests, allowing an attacker to replace these images undetected. The result is compromised build integrity and the risk of malicious code being embedded in the final output.
Affected Systems
The flaw affects the olm-operator-konflux-sample product. No specific vendor or product versions are listed, so all instances that use the default build configuration relying on mutable tags are potentially impacted.
Risk and Exploitability
Because the issue involves only the build process, the vulnerability does not grant direct remote code execution on deployed applications. The CVSS score of 4.2 indicates low severity, and no EPSS data is available. The analysis is inferred from the fact that an attacker would need to alter the image repository; without a KEV listing there is no evidence of active exploitation. Nevertheless, the potential for supply chain compromise means any organization using this operator should verify immutability of base images and restrict changes.
OpenCVE Enrichment