Impact
The vulnerability originates from the olm-operator-konflux-sample’s update_bundle.sh script. The script does not use fail‑fast shell options such as set -e or set -o pipefail, so when commands like skopeo or jq fail, the script continues execution. These silent failures can result in the bundle being updated with stale or incomplete data, causing data integrity problems within the system. The weakness is classified as CWE-252: Unchecked Return Value.
Affected Systems
The affected product is olm-operator-konflux-sample. No specific vendors, versions, or product families are listed, so the scope must be assumed to include all instances of this operator that use the bundled update script. Without version details the exact impact on particular deployments is uncertain.
Risk and Exploitability
The CVSS score of 2.6 indicates a low overall severity, and EPSS information is not available so the likelihood of exploitation is unclear. The flaw is not present in the CISA KEV catalog. The likely attack vector is an internal process that triggers bundle updates; an attacker who can influence the update script’s execution context could cause silent errors that corrupt the bundle data. The impact would be data integrity issues rather than unauthorized access or denial of service.
OpenCVE Enrichment