Omni manages Kubernetes on bare metal, virtual machines, or in a cloud. From 1.3.0 until 1.6.6 and 1.7.3, importing a standalone Talos cluster creates an ImportedClusterSecrets resource containing th…
High CVSS 7.6
Summary
Omni manages Kubernetes on bare metal, virtual machines, or in a cloud. From 1.3.0 until 1.6.6 and 1.7.3, importing a standalone Talos cluster creates an ImportedClusterSecrets resource containing the cluster's complete CA secrets bundle. The access rules in internal/backend/runtime/omni/state_access.go allow an authenticated user with the Reader role to retrieve the resource through ResourceService if the importing actor has not rotated those secrets, exposing Kubernetes, Talos, and etcd CA pr…
In-depth triage
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Sources
- NVD DATABASE
Original Links
- https://github.com/siderolabs/omni/commit/25fa9e141ee00285e70210ed40d11e4e457c871d
- https://github.com/siderolabs/omni/commit/a224cb020f3aaca2bc21c3e32a38eb4a37e531e8
- https://github.com/siderolabs/omni/commit/b8ca100c4539ea83f0ac2e53dcd523e6e5b68111
- https://github.com/siderolabs/omni/pull/2807
- https://github.com/siderolabs/omni/releases/tag/v1.6.6
- https://github.com/siderolabs/omni/releases/tag/v1.7.3
- https://github.com/siderolabs/omni/security/advisories/GHSA-wv8c-6mx2-xf4j
Timeline
- nvd_ingest NVD