{"id":"CVE-2025-2842","title":"A flaw was found in the Tempo Operator","summary":"A flaw was found in the Tempo Operator. When the Jaeger UI Monitor Tab functionality is enabled in a Tempo instance managed by the Tempo Operator, the Operator creates a ClusterRoleBinding for the Service Account of the Tempo instance to…","severity":"medium","cvss":4.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","cwe":["CWE-200"],"vendor":"Red Hat","product":"tempo-operator","affected":["tempo-operator < 0.15.3","rhosdt/tempo-rhel8-operator (all versions)","rhosdt/tempo-rhel8-operator (all versions)","rhosdt/tempo-gateway-opa-rhel8 (all versions)","rhosdt/tempo-gateway-rhel8 (all versions)","rhosdt/tempo-jaeger-query-rhel8 (all versions)","rhosdt/tempo-query-rhel8 (all versions)","rhosdt/tempo-rhel8 (all versions)"],"patched":["openshift_distributed_tracing 3.5.3"],"published":"2025-04-02","updated":"2026-09-08","sourceUpdated":"2026-09-08T22:17:36.747","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-2842","references":[{"url":"https://access.redhat.com/errata/RHSA-2025:3607","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2025:3740","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/security/cve/CVE-2025-2842","label":"secalert@redhat.com"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2355219","label":"secalert@redhat.com"},{"url":"https://github.com/grafana/tempo-operator/pull/1144","label":"secalert@redhat.com"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-2842.json"},{"url":"https://www.cve.org/CVERecord?id=CVE-2025-2842"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2025-2842"}],"tags":["nvd","cve.org","csaf","vex","red-hat"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2025-04-02T13:12:50.601180Z"},"epss":0.00383,"epssPercentile":0.32094,"ingestedAt":"2026-07-20T05:36:39.227Z","slug":"CVE-2025-2842","body":"## Overview\n\nA flaw was found in the Tempo Operator. When the Jaeger UI Monitor Tab functionality is enabled in a Tempo instance managed by the Tempo Operator, the Operator creates a ClusterRoleBinding for the Service Account of the Tempo instance to grant the cluster-monitoring-view ClusterRole.\nThis can be exploited if a user has 'create' permissions on TempoStack and 'get' permissions on Secret in a namespace (for example, a user has ClusterAdmin permissions for a specific namespace), as the user can read the token of the Tempo service account and therefore has access to see all cluster metrics.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Vendor advisories\n\n- **RHSA-2025:3607** · Red Hat · fixed in: Red Hat OpenShift distributed tracing 3.5.3 · released 2025-04-04 · [advisory](https://access.redhat.com/errata/RHSA-2025:3607)\n- **RHSA-2025:3740** · Red Hat · fixed in: Red Hat OpenShift distributed tracing 3.5.3 · released 2025-04-09 · [advisory](https://access.redhat.com/errata/RHSA-2025:3740)\n- **Red Hat VEX** · Moderate · affected: Red Hat OpenShift distributed tracing 3 · no fix planned: Red Hat OpenShift distributed tracing 3 · updated 2026-09-08 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-2842.json)","depth":"sunlit","depthScore":24,"depthScoreParts":{"impact":23.7,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}