Executive brief
The Ironic Standalone Operator, used to manage bare-metal infrastructure, contains a configuration flaw in its monitoring component. When the Prometheus metrics exporter is enabled, it listens on all network interfaces without authentication, potentially allowing unauthorized users on the same network to view operational data. This could lead to the exposure of sensitive system metrics and infrastructure details.
Technical details
The Ironic Standalone Operator (IrSO) Prometheus metrics exporter (introduced in v0.7.0) binds to 0.0.0.0 by default. Because the exporter does not implement an authentication mechanism, any host on an adjacent network can access the metrics endpoint if the feature is enabled. This is classified as CWE-668 (Exposure of Resource to Wrong Sphere). The vulnerability is particularly relevant when the pod runs with hostNetwork: true. Version 0.9.0 addresses this by introducing a configurable bindAddress field that defaults to the loopback interface (127.0.0.1).
Affected products
- Metal3-io ironic-standalone-operator >= 0.7.0, < 0.9.0
Timeline
- 2026-04-17: patched: Fix merged via Pull Request 635
- 2026-05-18: disclosed: Initial advisory publication
- 2026-05-29: advisory: GitHub Advisory reviewed and updated