Junglewise Threat Intelligence

Metal3 Ironic Standalone Operator unauthenticated metrics exposure

Severity: medium · CVSS 4.3 · Published 2026-05-29

Technologies: github.com/metal3-io/ironic-standalone-operator (Go). Vendors: Go.

Executive brief

The Ironic Standalone Operator, used to manage bare-metal infrastructure, contains a configuration flaw in its monitoring component. When the Prometheus metrics exporter is enabled, it listens on all network interfaces without authentication, potentially allowing unauthorized users on the same network to view operational data. This could lead to the exposure of sensitive system metrics and infrastructure details.

Technical details

The Ironic Standalone Operator (IrSO) Prometheus metrics exporter (introduced in v0.7.0) binds to 0.0.0.0 by default. Because the exporter does not implement an authentication mechanism, any host on an adjacent network can access the metrics endpoint if the feature is enabled. This is classified as CWE-668 (Exposure of Resource to Wrong Sphere). The vulnerability is particularly relevant when the pod runs with hostNetwork: true. Version 0.9.0 addresses this by introducing a configurable bindAddress field that defaults to the loopback interface (127.0.0.1).

Affected products

  • Metal3-io ironic-standalone-operator >= 0.7.0, < 0.9.0

Timeline

  • 2026-04-17: patched: Fix merged via Pull Request 635
  • 2026-05-18: disclosed: Initial advisory publication
  • 2026-05-29: advisory: GitHub Advisory reviewed and updated

References

Related threats