Impact
The release-service-utils component contains a Server‑Side Template Injection flaw that allows a malicious tenant to inject code into templates processed twice by a non‑sandboxed Jinja renderer. By manipulating specific input fields, an attacker can cause arbitrary code execution within the release‑service‑utils environment and potentially read stored credentials.
Affected Systems
All deployments that include the release‑service‑utils component are affected. Vendor, product, and version details were not provided, so the scope is limited to installations that use this component regardless of other system components.
Risk and Exploitability
The CVSS score of 8.2 indicates a high severity vulnerability. EPSS data is unavailable and the vulnerability is not listed in CISA KEV. The likely attack vector involves a malicious tenant who can submit data to the vulnerable input fields; successful exploitation would grant the attacker non‑privileged code execution within the component’s environment and the ability to read credentials stored therein.
OpenCVE Enrichment