CVE-2025-2842 - CVE House
Back to Database
Status published Medium CVE-2025-2842

Tempo-operator: tempo operator token exposition lead to read sensitive data

Vulnerability Description

A flaw was found in the Tempo Operator. When the Jaeger UI Monitor Tab functionality is enabled in a Tempo instance managed by the Tempo Operator, the Operator creates a ClusterRoleBinding for the Service Account of the Tempo instance to grant the cluster-monitoring-view ClusterRole. This can be exploited if a user has 'create' permissions on TempoStack and 'get' permissions on Secret in a namespace (for example, a user has ClusterAdmin permissions for a specific namespace), as the user can read the token of the Tempo service account and therefore has access to see all cluster metrics.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-2842

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

Red Hat OpenShift distributed tracing 3.5.1, Red Hat OpenShift distributed tracing 3
Vulnerable Versions:
0, sha256:233132300a9f5f019047a414b240f5b32c7563af8107bb52c4395892fdcd0fe0, sha256:be2ec2e3d3b21748cfe3b9382f7fc1f6c72d5f380fc97773518c254c6e5794ca

Timeline

Official Publish: April 2nd, 2025
Last Modified: March 22nd, 2026
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Weaknesses (CWE)