Impact
The flaw in konflux-operator-tasks allows the CI process to install the tkn command‑line interface directly from a network location without verifying its integrity. Without checksum or signature validation, a malicious actor who can compromise the distribution channel could replace the authentic binary with tampered code. This substitution would execute unauthorized instructions in the CI environment, potentially compromising downstream artifacts and pipelines. The weakness is a classic example of CWE‑494, where software installs untrusted code.
Affected Systems
Only the konflux-operator-tasks component is known to install tkn in this manner. Specific vendor or product release information is not provided, so any installation that follows the described pattern is susceptible. The environment that runs the CI process, regardless of underlying operating system, is affected when it follows the current download workflow.
Risk and Exploitability
The CVSS score of 2.6 indicates a low overall severity. No EPSS score is available and the vulnerability is not listed in CISA KEV, suggesting limited documented exploitation. However, the attack would require an adversary to compromise the network source from which tkn is downloaded, which is a higher barrier but still plausible in environments with weak network segmentation or poorly secured artifact repositories. The risk remains primarily through potential unauthorized execution within the CI pipeline.
OpenCVE Enrichment