Executive brief
The Ironic Standalone Operator, used to manage bare-metal hardware deployments, contains a flaw where its controller automatically modifies user-provided configuration files and security credentials without permission. This behavior allows a high-privilege system component to alter resources it does not own, potentially compromising the integrity of security certificates and environment settings. Organizations using this operator to manage their infrastructure may face unauthorized changes to sensitive configuration data.
Technical details
The Ironic Standalone Operator (IRSO) controller fails to perform proper authorization checks before modifying user-owned Kubernetes resources. Specifically, the controller automatically injects environment labels into user-provided Secrets and ConfigMaps (such as TLS certificates and BMC CA data) when they are referenced. This behavior constitutes a CWE-862 (Missing Authorization) vulnerability because a high-privilege controller is modifying resources without explicit consent from the resource owner. Attackers with low privileges on the network can trigger these modifications by referencing resources in Ironic deployments. The fix requires users to manually apply the 'ironic-standalone-operator.metal3.io/environment' label as a form of consent, otherwise, the operator will now reject the unlabeled resources. Patches are available in versions 0.7.3, 0.8.2, and 0.9.0.
Affected products
- metal3-io ironic-standalone-operator >= 0.7.0, <= 0.7.2; >= 0.8.0, <= 0.8.1
Timeline
- 2026-03-31: other: Initial security fix pull request opened
- 2026-05-12: patched: Fixes merged into release branches 0.7 and 0.8
- 2026-05-18: disclosed: Advisory published by maintainers
- 2026-05-29: advisory: GitHub Advisory reviewed and finalized
References
- https://github.com/metal3-io/ironic-standalone-operator/security/advisories/GHSA-hfc8-w5f4-3x6m
- https://github.com/metal3-io/ironic-standalone-operator/pull/619
- https://github.com/metal3-io/ironic-standalone-operator/pull/664
- https://github.com/metal3-io/ironic-standalone-operator/pull/665
- https://api.github.com/repos/metal3-io/ironic-standalone-operator/security-advisories/GHSA-hfc8-w5f4-3x6m