Impact
A flaw in konflux-operator-tasks allows Tekton task steps to run as root without proper security hardening. This absence of defense‑in‑depth controls, notably missing restrictions on capabilities or privilege escalation, leads to potential privilege escalation if an attacker can gain execution within that root process. The vulnerability is classified as CWE-250, indicating the ability to run code with elevated privileges.
Affected Systems
The affected system is the konflux-operator-tasks component used in Tekton pipelines. Any deployment of this component may be impacted since the CVE does not specify version ranges. Administrators should verify their Tekton task configurations for root execution of task steps.
Risk and Exploitability
The CVSS score of 2.6 reflects a low overall risk when considered alone, and no EPSS score is available to indicate exploitation likelihood. Because the flaw relies on a pre‑existing vulnerability within the root‑run process to be abused, the practical threat is limited unless other weaknesses exist. The patch is not listed in CISA KEV, suggesting no known widespread exploitation. Nevertheless, any untrusted Tekton tasks that run as root could be a vector for privilege escalation if combined with other vulnerabilities.
OpenCVE Enrichment