CVE-2025-2842
Description
A flaw was found in the Tempo Operator. When the Jaeger UI Monitor Tab functionality is enabled in a Tempo instance managed by the Tempo Operator, the Operator creates a ClusterRoleBinding for the Service Account of the Tempo instance to grant the cluster-monitoring-view ClusterRole. This can be exploited if a user has 'create' permissions on TempoStack and 'get' permissions on Secret in a namespace (for example, a user has ClusterAdmin permissions for a specific namespace), as the user can read the token of the Tempo service account and therefore has access to see all cluster metrics.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/grafana/tempo-operatorGo | < 0.16.0 | 0.16.0 |
Affected products
3- ghsa-coords2 versionspkg:golang/github.com/grafana/tempo-operatorpkg:rpm/opensuse/govulncheck-vulndb&distro=openSUSE%20Leap%2016.0
< 0.16.0+ 1 more
- (no CPE)range: < 0.16.0
- (no CPE)range: < 0.0.20260723T184607-160000.1.1
- Range: < 0.16.0
Patches
Vulnerability mechanics
References
9- github.com/advisories/GHSA-5xf3-gmx4-529vghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2025-2842ghsaADVISORY
- access.redhat.com/errata/RHSA-2025:3607nvdWEB
- access.redhat.com/errata/RHSA-2025:3740nvdWEB
- access.redhat.com/security/cve/CVE-2025-2842nvdWEB
- bugzilla.redhat.com/show_bug.cginvdWEB
- github.com/grafana/tempo-operator/blob/8d1c7f13cb0f8db490144b04665b1fd6a2d56307/CHANGELOG.mdghsaWEB
- github.com/grafana/tempo-operator/commit/60b538c45f76755262e211d8df0e601a716308c7ghsaWEB
- github.com/grafana/tempo-operator/pull/1144nvdWEB
News mentions
0No linked articles in our index yet.