VYPR

open-feature-operator

by open-feature

Source repositories

CVEs (2)

  • CVE-2023-29018HigApr 14, 2023
    risk 0.45cvss 8.0epss 0.01

    The OpenFeature Operator allows users to expose feature flags to applications. Assuming the pre-existence of a vulnerability that allows for arbitrary code execution, an attacker could leverage the lax permissions configured on `open-feature-operator-controller-manager` to…

  • CVE-2026-54495medJul 15, 2026
    risk 0.26cvss epss

    ## Summary A namespaced `FeatureFlagSource` or `InProcessConfiguration` resource can be referenced cross-namespace via the `openfeature.dev/featureflagsource` annotation using the documented `{NAMESPACE}/{NAME}` syntax. The operator resolves the referenced resource cluster-wide…