CVE-2025-2786 Information
Apr 03, 2025
cve
Description
A flaw was found in Tempo Operator where it creates a ServiceAccount ClusterRole and ClusterRoleBinding when a user deploys a TempoStack or TempoMonolithic instance. This flaw allows a user with full access to their namespace to extract the ServiceAccount token and use it to submit TokenReview and SubjectAccessReview requests potentially revealing information about other users’ permissions. While this does not allow privilege escalation or impersonation it exposes information that could aid in gathering information for further attacks.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Reference
https://access.redhat.com/security/cve/CVE-2025-2786 https://bugzilla.redhat.com/show_bug.cgi?id=2354811
Attack Complexity
LOW
Privileges Required
LOW
User Interaction Required
LOW
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
LOW
Availability Impact
NONE
Base Score
NONE
Base Severity
4.3
Share on: