Impact
The flaw allows bundle builds to download external, unverified resources because the hermetic build mode is disabled by default. This means that during a build, code or artifacts that have not been vetted by the developer can be incorporated into the final product, potentially introducing malicious or unintended content. The weakness is a lack of restriction on external fetches, which can compromise the integrity and trustworthiness of software artifacts.
Affected Systems
The vulnerability affects the olm-operator-konflux-sample project. No specific version information is provided, so all current versions of this component are potentially impacted until a patch or configuration change is applied.
Risk and Exploitability
The CVSS score of 2.6 indicates a low overall severity. The EPSS score is unavailable, and the vulnerability is not listed in the CISA KEV catalog, suggesting that it is not widely exploited at present. The attack vector is inferred to be an attacker who can influence the build configuration or supply untrusted resources to the build environment. By manipulating the sources used during the build, an adversary could inject malicious code into the resulting artifacts, creating a supply chain risk for downstream users.
OpenCVE Enrichment