CVE-2025-2786

CVSS 3.1 Score 4.3 of 10 (medium)

Details

Published Apr 2, 2025
Updated: Apr 9, 2025
CWE ID 200

Summary

CVE-2025-2786 is a vulnerability affecting Tempo Operator. When a user deploys TempoStack or TempoMonolithic instance, Tempo Operator creates a ServiceAccount, ClusterRole, and ClusterRoleBinding. This flaw enables users with full access to their namespace to extract the ServiceAccount token and submit unauthorized TokenReview and SubjectAccessReview requests. Although it does not grant privilege escalation or impersonation, it exposes sensitive information about other users' permissions, potentially aiding in further attacks.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share