CVE-2025-29781 PUBLISHED CVSS 6.5 MEDIUM

Bare Metal Operator (BMO) can expose any secret from other namespaces via BMCEventSubscription CRD

EPSS 0.05% · 16.1th percentile

Risk Scores

CVSS v3.1
6.5
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
EPSS Score
0.05%
16.1th percentile

Affected Products

VendorProductVersions
github.commetal3-io/baremetal-operator/apis0, 0.9.0, 0
metal3-iobaremetal-operator= 0.9.0, *, *

Timeline

References

Open in Interactive Console →