CVE-2025-2842

CVSS 3.1 Score 4.3 of 10 (medium)

Details

Published Apr 2, 2025
Updated: Apr 9, 2025
CWE ID 200

Summary

CVE-2025-2842 reveals a vulnerability in the Tempo Operator. The issue arises when enabling the Jaeger UI Monitor Tab functionality in a Tempo instance. The Tempo Operator generates a ClusterRoleBinding for the Tempo instance's Service Account, granting the cluster-monitoring-view ClusterRole. An attacker with 'create' permissions on TempoStack and 'get' permissions on Secrets in a specific namespace can exploit this vulnerability. By reading the Tempo service account token, the attacker gains access to all cluster metrics.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share