PT-2023-22996 · Ironic+1 · Ironic+2
Tuminoid
·
Published
2023-04-26
·
Updated
2023-05-09
·
CVE-2023-30841
CVSS v3.1
6.0
Medium
| Vector | AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Baremetal Operator versions prior to 0.3.0
Description
The issue arises from the storage of
.htpasswd files as ConfigMaps instead of Secrets by ironic and ironic-inspector deployed within Baremetal Operator using the included deploy.sh. This causes the plain-text username and hashed password to be readable by anyone having a cluster-wide read-access to the management cluster, or access to the management cluster's Etcd storage.Recommendations
For versions prior to 0.3.0, update to version 0.3.0 or later to resolve the issue.
As a temporary workaround, users may modify the kustomizations and redeploy the BMO, or recreate the required ConfigMaps as Secrets per instructions in baremetal-operator PR#1241.
Exploit
Fix
Cleartext Transmission of Sensitive Information
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Baremetal Operator
Ironic
Ironic-Inspector