Impact
The flaw in olm-operator-konflux-sample allows its bundle builder stage to install or upgrade Python packages using pip without pinning specific versions or verifying package hashes. This lack of version control and hash checking permits a malicious or compromised package to enter the build process unnoticed, potentially inserting untrusted code into the final software artifact and creating a supply‑chain vulnerability.
Affected Systems
The vulnerability affects the olm-operator-konflux-sample bundle builder used in operator deployments. No specific product version information is included in the advisory, so any release that uses the unpatched bundle builder stage is potentially impacted.
Risk and Exploitability
With a CVSS score of 2.6, the severity is low, but the risk remains because the compromise occurs at build time, allowing malicious code to be embedded into software distributed to customers. The attack vector likely requires the attacker to supply malicious Python packages to the build environment or manipulate the dependency sources, which can be achieved if the build environment or package registry is compromised. The EPSS score is not available, and the vulnerability is not listed as a known exploited vulnerability in CISA’s KEV catalog.
OpenCVE Enrichment