Impact
The flaw resides in konflux-operator-tasks: its GitHub workflows do not specify explicit least-privilege permissions, causing them to inherit broader access tokens by default. This oversight can let an attacker obtain unauthorized access or execute actions beyond the intended scope, potentially leading to information disclosure or unauthorized modifications.
Affected Systems
konflux-operator-tasks is the affected component. No specific version information is provided in the current advisory, so all deployed instances of this component are potentially impacted.
Risk and Exploitability
The CVSS score of 2.6 indicates low severity, and the EPSS score is not available, suggesting limited likelihood of widespread exploitation. The vulnerability is not listed in the CISA KEV catalog. If an attacker can inject code or manipulate events in the GitHub workflows, the default token privileges could be leveraged to access settings, secrets, or repository contents, which is inferred from the description.
OpenCVE Enrichment