CVE-2025-2786
CVSS 3.1 Score 4.3 of 10 (medium)
Details
Published Apr 2, 2025
Updated: Apr 9, 2025
CWE ID 200
Summary
CVE-2025-2786 is a vulnerability affecting Tempo Operator. When a user deploys TempoStack or TempoMonolithic instance, Tempo Operator creates a ServiceAccount, ClusterRole, and ClusterRoleBinding. This flaw enables users with full access to their namespace to extract the ServiceAccount token and submit unauthorized TokenReview and SubjectAccessReview requests. Although it does not grant privilege escalation or impersonation, it exposes sensitive information about other users' permissions, potentially aiding in further attacks.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.