CVE-2025-2786 - CVE House
Back to Database
Status published Medium CVE-2025-2786

Tempo-operator: serviceaccount token exposure leading to token and subject access reviews in openshift tempo operator

Vulnerability Description

A flaw was found in Tempo Operator, where it creates a ServiceAccount, ClusterRole, and ClusterRoleBinding when a user deploys a TempoStack or TempoMonolithic instance. This flaw allows a user with full access to their namespace to extract the ServiceAccount token and use it to submit TokenReview and SubjectAccessReview requests, potentially revealing information about other users' permissions. While this does not allow privilege escalation or impersonation, it exposes information that could aid in gathering information for further attacks.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-2786

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

Red Hat OpenShift distributed tracing 3.5.1, Red Hat OpenShift distributed tracing 3
Vulnerable Versions:
0, sha256:233132300a9f5f019047a414b240f5b32c7563af8107bb52c4395892fdcd0fe0, sha256:be2ec2e3d3b21748cfe3b9382f7fc1f6c72d5f380fc97773518c254c6e5794ca

Timeline

Official Publish: April 2nd, 2025
Last Modified: March 22nd, 2026
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Weaknesses (CWE)