Cleartext storage of sensitive information in Baremetal Operator - CVE-2023-30841
Published: May 18, 2023
Vulnerability details
The vulnerability allows a local user to gain access to sensitive information.
The vulnerability exists due to ironic and ironic-inspector deployed within Baremetal Operator using the
included `deploy.sh` store their `.htpasswd` files as ConfigMaps
instead of Secrets. A local user can obtain credentials and use them to compromise the application.
Affected software
Red Hat OpenShift Container Platform
How to mitigate CVE-2023-30841
Red Hat OpenShift Container Platform - addressed in versions 4.12.58, 4.13.0, 4.14.0