VYPR

Go modules package

github.com/grafana/tempo-operator

pkg:golang/github.com/grafana/tempo-operator

Vulnerabilities (2)

  • CVE-2025-2842MedApr 2, 2025
    affected < 0.16.0fixed 0.16.0

    A flaw was found in the Tempo Operator. When the Jaeger UI Monitor Tab functionality is enabled in a Tempo instance managed by the Tempo Operator, the Operator creates a ClusterRoleBinding for the Service Account of the Tempo instance to grant the cluster-monitoring-view ClusterR

  • CVE-2025-2786MedApr 2, 2025
    affected < 0.16.0fixed 0.16.0

    A flaw was found in Tempo Operator, where it creates a ServiceAccount, ClusterRole, and ClusterRoleBinding when a user deploys a TempoStack or TempoMonolithic instance. This flaw allows a user with full access to their namespace to extract the ServiceAccount token and use it to s