CVE-2025-2842
CVSS 3.1 Score 4.3 of 10 (medium)
Details
Published Apr 2, 2025
Updated: Apr 9, 2025
CWE ID 200
Summary
CVE-2025-2842 reveals a vulnerability in the Tempo Operator. The issue arises when enabling the Jaeger UI Monitor Tab functionality in a Tempo instance. The Tempo Operator generates a ClusterRoleBinding for the Tempo instance's Service Account, granting the cluster-monitoring-view ClusterRole. An attacker with 'create' permissions on TempoStack and 'get' permissions on Secrets in a specific namespace can exploit this vulnerability. By reading the Tempo service account token, the attacker gains access to all cluster metrics.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.