—
GO-2024-3109
The Bare Metal Operator (BMO) can expose particularly named secrets from other namespaces via BMH CRD in github.com/metal3-io/baremetal-operator
Quick fix
GO-2024-3109 — github.com/metal3-io/baremetal-operator: upgrade to the fixed version with the command below.
go get github.com/metal3-io/baremetal-operator@v0.5.2Details
The Bare Metal Operator (BMO) can expose particularly named secrets from other namespaces via BMH CRD in github.com/metal3-io/baremetal-operator
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/metal3-io/baremetal-operator
Introduced in:
0Fixed in: 0.5.2Fix
go get github.com/metal3-io/baremetal-operator@v0.5.2References
- https://github.com/metal3-io/baremetal-operator/security/advisories/GHSA-pqfh-xh7w-7h3p[ADVISORY]
- https://nvd.nist.gov/vuln/detail/CVE-2024-43803[ADVISORY]
- https://github.com/metal3-io/baremetal-operator/commit/3af4882e9c5fadc1a7550f53daea21dccd271f74[FIX]
- https://github.com/metal3-io/baremetal-operator/commit/bedae7b997d16f36e772806681569bb8eb4dadbb[FIX]
- https://github.com/metal3-io/baremetal-operator/commit/c2b5a557641bc273367635124047d6c958aa15f7[FIX]
- https://github.com/metal3-io/baremetal-operator/pull/1929[FIX]
- https://github.com/metal3-io/baremetal-operator/pull/1930[FIX]
- https://github.com/metal3-io/baremetal-operator/pull/1931[FIX]