PT-2023-22996 · Ironic+1 · Ironic+2

Tuminoid

·

Published

2023-04-26

·

Updated

2023-05-09

·

CVE-2023-30841

CVSS v3.1

6.0

Medium

VectorAV:L/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Baremetal Operator versions prior to 0.3.0
Description The issue arises from the storage of .htpasswd files as ConfigMaps instead of Secrets by ironic and ironic-inspector deployed within Baremetal Operator using the included deploy.sh. This causes the plain-text username and hashed password to be readable by anyone having a cluster-wide read-access to the management cluster, or access to the management cluster's Etcd storage.
Recommendations For versions prior to 0.3.0, update to version 0.3.0 or later to resolve the issue. As a temporary workaround, users may modify the kustomizations and redeploy the BMO, or recreate the required ConfigMaps as Secrets per instructions in baremetal-operator PR#1241.

Exploit

Fix

Cleartext Transmission of Sensitive Information

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2023-30841
GHSA-9WH7-397J-722M

Affected Products

Baremetal Operator
Ironic
Ironic-Inspector