Impact
The vulnerability arises when GitHub Actions in the konflux-operator-tasks component reference mutable tags or branches instead of specific commit SHAs. This oversight permits a remote actor, if able to modify the referenced tag or branch, to inject malicious code into the build pipeline. The result could be the execution of unauthorized code or corruption of the build artifacts, compromising the integrity of the affected system.
Affected Systems
The flaw targets the konflux-operator-tasks project. No specific product versions or vendor details are listed in the CNA data; therefore, any installation of this component that relies on GitHub Actions with mutable references is potentially impacted.
Risk and Exploitability
The CVSS score of 4.2 places this issue in the low‑to‑moderate severity range. Because EPSS data is not available and the vulnerability is not listed in CISA KEV, the likelihood of exploitation is uncertain, but the remote path via compromised tags or branches is feasible. Attackers need only influence the mutable reference in the CI definition to achieve the impact described.
OpenCVE Enrichment