Database/Control plane, storage & DevOps
Sidero Omni: Reader role can read the full CA secrets bundle of an imported Talos cluster
Impact
Importing a standalone Talos cluster stores the cluster's complete CA secrets bundle in an ImportedClusterSecrets resource, and the access rules let any authenticated user with the Reader role fetch it through ResourceService when the importing actor has not rotated the secrets. That hands over the Kubernetes, Talos and etcd CA private keys plus the service-account key. With the Kubernetes CA key an attacker signs a certificate for system:masters and owns the imported cluster outside Omni's authorization boundary - every workload on it, and every credential and secret it holds. For an operator running GPU clusters under Omni, a low-privilege console account becomes full cluster admin on any imported cluster.
Who can reach it
Any authenticated Omni user holding the Reader role who can call ResourceService. Affects imported standalone Talos clusters whose secrets were never rotated after import.
What to do
Upgrade Omni to 1.6.6 or 1.7.3. Versions from 1.3.0 up to those releases are affected. Upgrading alone does not undo prior exposure: rotate the CA secrets of any cluster imported before the upgrade, since the keys may already have been read. This is a management-plane service upgrade, not a fleet-wide node action.
References
Related entries
- rsync SSL modes: server TLS certificates are not validated, so an on-path attacker can read the transferCVE-2026-70454 · rsync (openssl mode) and rsync-ssl (stunnel mode) TLS server certificate validationHigh
- OpenZFS (sharenfs export generation): When an NFS share is exported to IPv6 addresses via sharenfs, OpenZFS silentlyCVE-2013-20001 · OpenZFS (sharenfs export generation)High
- Ceph CephX authentication protocol: An attacker who sniffs the storage network can replay a CephX authenticationCVE-2018-1128 · Ceph CephX authentication protocolHigh
- Emerson/Vertiv Liebert IntelliSlot Web Card (config/configUser.htm, config/configTelnet.htm): The IntelliSlot cardCVE-2018-12922 · Emerson/Vertiv Liebert IntelliSlot Web Card (config/configUser.htm, config/configTelnet.htm)High
- ntpd (protocol engine, zero-origin timestamp): Continually sending packets with a zero-origin timestamp lets a remoteCVE-2018-7185 · ntpd (protocol engine, zero-origin timestamp)High
- Ceph RADOS Gateway (RGW, Beast frontend): An unauthenticated client can crash radosgw by sending valid headers followedCVE-2019-10222 · Ceph RADOS Gateway (RGW, Beast frontend)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.