SB2025032534 - Information disclosure in Baremetal Operator
Published: March 25, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Information disclosure (CVE-ID: CVE-2025-29781)
The vulnerability allows a local user to gain access to potentially sensitive information.
The vulnerability exists due to the Bare Metal Operator (BMO) can expose any secret from other namespaces via BMCEventSubscription CRD. A local user can gain unauthorized access to sensitive information on the system.
Remediation
Install update from vendor's website.
References
- https://github.com/metal3-io/baremetal-operator/commit/19f8443b1fe182f76dd81b43122e8dd102f8b94c
- https://github.com/metal3-io/baremetal-operator/pull/2321
- https://github.com/metal3-io/baremetal-operator/pull/2322
- https://github.com/metal3-io/baremetal-operator/security/advisories/GHSA-c98h-7hp9-v9hq
- https://github.com/metal3-io/metal3-docs/blob/main/design/baremetal-operator/bmc-events.md