| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-49pm-43hf-6xfq | IPAM controller service account granted unnecessary full access to Secrets |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Sat, 13 Jun 2026 04:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 12 Jun 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Metal3-io
Metal3-io ip-address-manager |
|
| Vendors & Products |
Metal3-io
Metal3-io ip-address-manager |
Fri, 12 Jun 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | IPAM is the IP address Manager for Cluster API Provider Metal3. Prior to versions 1.11.7, 1.12.4, and 1.13.0, the IPAM controller's ClusterRole granted full CRUD permissions (create, delete, get, list, patch, update, watch) on core/v1 Secrets. The controller never accesses Secrets during normal operation. If the controller pod were compromised (e.g. via supply chain attack or container escape), an attacker could leverage these excessive permissions to read, modify, or delete Secrets in the namespace, potentially exposing credentials and other sensitive data. This issue has been patched in versions 1.11.7, 1.12.4, and 1.13.0. | |
| Title | IPAM controller service account granted unnecessary full access to Secrets | |
| Weaknesses | CWE-250 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-06-13T03:18:15.986Z
Reserved: 2026-05-18T22:07:37.435Z
Link: CVE-2026-47190
Updated: 2026-06-13T03:18:09.572Z
Status : Awaiting Analysis
Published: 2026-06-12T16:16:29.643
Modified: 2026-06-12T16:24:31.187
Link: CVE-2026-47190
No data.
OpenCVE Enrichment
Updated: 2026-06-12T20:20:05Z
Github GHSA