Metal3-Io Baremetal-Operator vulnerabilities

3 known vulnerabilities affecting metal3-io/baremetal-operator.

Total CVEs
3
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
MEDIUM3

Vulnerabilities

Page 1 of 1
CVE-2025-29781MEDIUMCVSS 6.5v= 0.9.0fixed in 0.8.12025-03-17
CVE-2025-29781 [MEDIUM] CWE-200 CVE-2025-29781: The Bare Metal Operator (BMO) implements a Kubernetes API for managing bare metal hosts in Metal3. B The Bare Metal Operator (BMO) implements a Kubernetes API for managing bare metal hosts in Metal3. Baremetal Operator enables users to load Secret from arbitrary namespaces upon deployment of the namespace scoped Custom Resource `BMCEventSubscription`. Prior to versions 0.8.1 and 0.9.1, an adversary Kubernetes account with only namespace level roles
nvd
CVE-2024-43803MEDIUMCVSS 4.9v>= 0.7.0, < 0.8.0v>= 0.6.0, < 0.6.2+1 more2024-09-03
CVE-2024-43803 [MEDIUM] CWE-200 CVE-2024-43803: The Bare Metal Operator (BMO) implements a Kubernetes API for managing bare metal hosts in Metal3. T The Bare Metal Operator (BMO) implements a Kubernetes API for managing bare metal hosts in Metal3. The `BareMetalHost` (BMH) CRD allows the `userData`, `metaData`, and `networkData` for the provisioned host to be specified as links to Kubernetes Secrets. There are fields for both the `Name` and `Namespace` of the Secret, meaning that versions of the
nvd
CVE-2023-30841MEDIUMCVSS 5.5fixed in 0.3.02023-04-26
CVE-2023-30841 [MEDIUM] CWE-200 CVE-2023-30841: Baremetal Operator (BMO) is a bare metal host provisioning integration for Kubernetes. Prior to vers Baremetal Operator (BMO) is a bare metal host provisioning integration for Kubernetes. Prior to version 0.3.0, ironic and ironic-inspector deployed within Baremetal Operator using the included `deploy.sh` store their `.htpasswd` files as ConfigMaps instead of Secrets. This causes the plain-text username and hashed password to be readable by anyone h
nvd