VDB
GO-2025-3530
GO-2025-3530
PUBLISHED
Bare Metal Operator (BMO) can expose any secret from other namespaces via BMCEventSubscription CRD in github.com/metal3-io/baremetal-operator/apis
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| github.com | metal3-io/baremetal-operator/apis | 0, 0.9.0, 0 |
Timeline
- Mar 18, 2025 CVE Published
- Mar 3, 2026 CVE Updated
References
- https://github.com/metal3-io/baremetal-operator/security/advisories/GHSA-c98h-7hp9-v9hq advisory
- https://github.com/metal3-io/baremetal-operator/commit/19f8443b1fe182f76dd81b43122e8dd102f8b94c url
- https://github.com/metal3-io/baremetal-operator/pull/2321 url
- https://github.com/metal3-io/baremetal-operator/pull/2322 url
- https://github.com/metal3-io/metal3-docs/blob/main/design/baremetal-operator/bmc-events.md url