VYPR

Tempo Operator

by Grafana

Source repositories

CVEs (2)

  • CVE-2025-2842MedApr 2, 2025
    risk 0.21cvss 4.3epss 0.00

    A flaw was found in the Tempo Operator. When the Jaeger UI Monitor Tab functionality is enabled in a Tempo instance managed by the Tempo Operator, the Operator creates a ClusterRoleBinding for the Service Account of the Tempo instance to grant the cluster-monitoring-view…

  • CVE-2025-2786MedApr 2, 2025
    risk 0.21cvss 4.3epss 0.00

    A flaw was found in Tempo Operator, where it creates a ServiceAccount, ClusterRole, and ClusterRoleBinding when a user deploys a TempoStack or TempoMonolithic instance. This flaw allows a user with full access to their namespace to extract the ServiceAccount token and use it to…