Security Flaw in Tempo Operator Affecting Cluster Monitoring Permissions
CVE-2025-2842
4.3MEDIUM
Summary
A security flaw exists within the Tempo Operator that affects systems utilizing the Jaeger UI Monitor Tab functionality. When this feature is enabled, the Operator incorrectly creates a ClusterRoleBinding for the corresponding Tempo instance's Service Account, granting it access to the cluster-monitoring-view ClusterRole. This vulnerability can be exploited by users with 'create' permissions on TempoStack and 'get' permissions on Secrets in a specified namespace, permitting them to access the token for Tempo's service account. Consequently, these users can view all cluster metrics, leading to potential exposure of sensitive monitoring data.
References
CVSS V3.1
Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved