Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-47190

Опубликовано: 12 июн. 2026
Источник: redhat
CVSS3: 6.4

Описание

IPAM is the IP address Manager for Cluster API Provider Metal3. Prior to versions 1.11.7, 1.12.4, and 1.13.0, the IPAM controller's ClusterRole granted full CRUD permissions (create, delete, get, list, patch, update, watch) on core/v1 Secrets. The controller never accesses Secrets during normal operation. If the controller pod were compromised (e.g. via supply chain attack or container escape), an attacker could leverage these excessive permissions to read, modify, or delete Secrets in the namespace, potentially exposing credentials and other sensitive data. This issue has been patched in versions 1.11.7, 1.12.4, and 1.13.0.

A flaw was found in the Cluster API Provider Metal3 IP Address Manager (IPAM) controller. The controller's ClusterRole granted excessive permissions, allowing full create, read, update, and delete (CRUD) access to core/v1 Secrets. If the controller pod were compromised, an attacker could leverage these permissions to read, modify, or delete sensitive data within the namespace. This could lead to the exposure of credentials and other sensitive information.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Multicluster Engine for Kubernetesmulticluster-engine/capoa-bootstrap-rhel9Fix deferred
Red Hat OpenShift Container Platform 4openshift4/ose-baremetal-cluster-api-controllers-rhel9Fix deferred
Red Hat OpenShift Container Platform 4openshift4/ose-baremetal-machine-controllersFix deferred
Red Hat OpenShift Container Platform 4openshift4/ose-baremetal-machine-controllers-rhel9Fix deferred
Red Hat OpenShift Container Platform 4openshift4/ose-cluster-capi-rhel9-operatorFix deferred
Red Hat OpenShift Container Platform 4openshift4/ose-machine-api-operatorFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-266
https://bugzilla.redhat.com/show_bug.cgi?id=2488412github.com/metal3-io/ip-address-manager: Cluster API Provider Metal3 IPAM: Information disclosure via excessive permissions on Secrets

6.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.4
nvd
около 2 месяцев назад

IPAM is the IP address Manager for Cluster API Provider Metal3. Prior to versions 1.11.7, 1.12.4, and 1.13.0, the IPAM controller's ClusterRole granted full CRUD permissions (create, delete, get, list, patch, update, watch) on core/v1 Secrets. The controller never accesses Secrets during normal operation. If the controller pod were compromised (e.g. via supply chain attack or container escape), an attacker could leverage these excessive permissions to read, modify, or delete Secrets in the namespace, potentially exposing credentials and other sensitive data. This issue has been patched in versions 1.11.7, 1.12.4, and 1.13.0.

CVSS3: 4.4
github
2 месяца назад

IPAM controller service account granted unnecessary full access to Secrets

6.4 Medium

CVSS3