---
id: CVE-2025-2842
title: A flaw was found in the Tempo Operator
summary: >-
  A flaw was found in the Tempo Operator. When the Jaeger UI Monitor Tab
  functionality is enabled in a Tempo instance managed by the Tempo Operator,
  the Operator creates a ClusterRoleBinding for the Service Account of the Tempo
  instance to…
severity: medium
cvss: 4.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'
cwe:
  - CWE-200
vendor: Red Hat
product: tempo-operator
affected:
  - tempo-operator < 0.15.3
  - rhosdt/tempo-rhel8-operator (all versions)
  - rhosdt/tempo-rhel8-operator (all versions)
  - rhosdt/tempo-gateway-opa-rhel8 (all versions)
  - rhosdt/tempo-gateway-rhel8 (all versions)
  - rhosdt/tempo-jaeger-query-rhel8 (all versions)
  - rhosdt/tempo-query-rhel8 (all versions)
  - rhosdt/tempo-rhel8 (all versions)
patched:
  - openshift_distributed_tracing 3.5.3
published: '2025-04-02'
updated: '2026-09-08'
sourceUpdated: '2026-09-08T22:17:36.747'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-2842'
references:
  - url: 'https://access.redhat.com/errata/RHSA-2025:3607'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:3740'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/security/cve/CVE-2025-2842'
    label: secalert@redhat.com
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2355219'
    label: secalert@redhat.com
  - url: 'https://github.com/grafana/tempo-operator/pull/1144'
    label: secalert@redhat.com
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-2842.json
  - url: 'https://www.cve.org/CVERecord?id=CVE-2025-2842'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2025-2842'
tags:
  - nvd
  - cve.org
  - csaf
  - vex
  - red-hat
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2025-04-02T13:12:50.601180Z'
epss: 0.00383
epssPercentile: 0.29517
ingestedAt: '2026-07-20T05:36:39.227Z'
---

## Overview

A flaw was found in the Tempo Operator. When the Jaeger UI Monitor Tab functionality is enabled in a Tempo instance managed by the Tempo Operator, the Operator creates a ClusterRoleBinding for the Service Account of the Tempo instance to grant the cluster-monitoring-view ClusterRole.
This can be exploited if a user has 'create' permissions on TempoStack and 'get' permissions on Secret in a namespace (for example, a user has ClusterAdmin permissions for a specific namespace), as the user can read the token of the Tempo service account and therefore has access to see all cluster metrics.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Vendor advisories

- **RHSA-2025:3607** · Red Hat · fixed in: Red Hat OpenShift distributed tracing 3.5.3 · released 2025-04-04 · [advisory](https://access.redhat.com/errata/RHSA-2025:3607)
- **RHSA-2025:3740** · Red Hat · fixed in: Red Hat OpenShift distributed tracing 3.5.3 · released 2025-04-09 · [advisory](https://access.redhat.com/errata/RHSA-2025:3740)
- **Red Hat VEX** · Moderate · affected: Red Hat OpenShift distributed tracing 3 · no fix planned: Red Hat OpenShift distributed tracing 3 · updated 2026-09-08 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-2842.json)
