CVE-2025-29781MEDIUM≥ 0.9.0, < 0.9.1·≥ 0, < 0.8.12025-03-17
CVE-2025-29781 [MEDIUM] CWE-200 Bare Metal Operator (BMO) can expose any secret from other namespaces via BMCEventSubscription CRD
Bare Metal Operator (BMO) can expose any secret from other namespaces via BMCEventSubscription CRD
### Impact
The Bare Metal Operator (BMO) implements a Kubernetes API for managing bare metal hosts in Metal3.
Baremetal Operator enables users to load Secret from arbitrary namespaces upon deployment of the namespace scoped Custom Resource `BMCEventSubscription` (BMC
ghsaosv