GHSA-856v-8qm2-9wjv
MEDIUMCVE-2025-7195Early versions of Operator-SDK provided an insecure method to allow operator containers to run in environments that used a random UID. Operator-SDK before 0.15.2 provided a script, usersetup, which modifies the permissions of the /etc/passwd file to 664 during build time. Developers who used Operator-SDK before 0.15.2 to scaffold their operator may still be impacted by this if the insecure userset
- Affected
- >=0, <0.15.2
- Fixed in
- 0.15.2
- Weakness
- CWE-276
- Published
- 2025-08-07
- Source
- github