A flaw was found in the Tempo Operator. When the Jaeger UI Monitor Tab functionality is enabled in a Tempo instance managed by the Tempo Operator, the Operator creates a ClusterRoleBinding for the Service Account of the Tempo instance to grant the cluster-monitoring-view ClusterRole.
This can be exploited if a user has 'create' permissions on TempoStack and 'get' permissions on Secret in a namespace (for example, a user has ClusterAdmin permissions for a specific namespace), as the user can read the token of the Tempo service account and therefore has access to see all cluster metrics.
References
Configurations
No configuration.
History
09 Apr 2025, 21:16
Type | Values Removed | Values Added |
---|---|---|
References |
|
04 Apr 2025, 14:15
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
|
References |
|
02 Apr 2025, 12:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-04-02 12:15
Updated : 2025-04-09 21:16
NVD link : CVE-2025-2842
Mitre link : CVE-2025-2842
CVE.ORG link : CVE-2025-2842
JSON object : View
Products Affected
No product.
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor