GHSA-9wh7-397j-722m
Ironic and ironic-inspector may expose as ConfigMaps
Quick fix
GHSA-9wh7-397j-722m — github.com/metal3-io/baremetal-operator: upgrade to the fixed version with the command below.
go get github.com/metal3-io/baremetal-operator@v0.3.0Details
### Impact Ironic and ironic-inspector deployed within Baremetal Operator using the included `deploy.sh` store their `.htpasswd` files as ConfigMaps instead of Secrets. This causes the plain-text username and hashed password to be readable by anyone having a cluster-wide read-access to the management cluster, or access to the management cluster's Etcd storage.
### Patches This issue is patched in [baremetal-operator PR#1241](https://github.com/metal3-io/baremetal-operator/pull/1241), and is included in BMO release 0.3.0 onwards.
### Workarounds User may modify the kustomizations and redeploy the BMO, or recreate the required ConfigMaps as Secrets per instructions in [baremetal-operator PR#1241](https://github.com/metal3-io/baremetal-operator/pull/1241)
Are you affected?
Enter the version of the package you're using.
Affected packages
0Fixed in: 0.3.0go get github.com/metal3-io/baremetal-operator@v0.3.0