Medium severity4.3GHSA Advisory· Published Apr 2, 2025· Updated Jul 20, 2026
CVE-2025-2786
CVE-2025-2786
Description
A flaw was found in Tempo Operator, where it creates a ServiceAccount, ClusterRole, and ClusterRoleBinding when a user deploys a TempoStack or TempoMonolithic instance. This flaw allows a user with full access to their namespace to extract the ServiceAccount token and use it to submit TokenReview and SubjectAccessReview requests, potentially revealing information about other users' permissions. While this does not allow privilege escalation or impersonation, it exposes information that could aid in gathering information for further attacks.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/grafana/tempo-operatorGo | < 0.16.0 | 0.16.0 |
Affected products
3- ghsa-coords2 versionspkg:golang/github.com/grafana/tempo-operatorpkg:rpm/opensuse/govulncheck-vulndb&distro=openSUSE%20Leap%2016.0
< 0.16.0+ 1 more
- (no CPE)range: < 0.16.0
- (no CPE)range: < 0.0.20260723T184607-160000.1.1
- Range: < 0.16.0
Patches
Vulnerability mechanics
References
8- github.com/advisories/GHSA-28gr-56hr-prp6ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2025-2786ghsaADVISORY
- access.redhat.com/errata/RHSA-2025:3607nvdWEB
- access.redhat.com/errata/RHSA-2025:3740nvdWEB
- access.redhat.com/security/cve/CVE-2025-2786nvdWEB
- bugzilla.redhat.com/show_bug.cginvdWEB
- github.com/grafana/tempo-operator/commit/0f3f6ad9dec457d67c3d45ceec90e8dfa017329cghsaWEB
- github.com/grafana/tempo-operator/pull/1145nvdWEB
News mentions
0No linked articles in our index yet.