THREATOPS
THREAT OPSThreat News › [NVD] CVE-2025-2842 (MEDIUM 4.3) — A flaw was found in the Tempo Operator. When the Jaeger UI Monitor Tab functionality is enabled in a Tempo instance managed by the Tempo Operator, the Operator creates a ClusterRoleBinding for the Service Account of the Tempo instance to grant the cluster-monitoring-view ClusterR

[NVD] CVE-2025-2842 (MEDIUM 4.3) — A flaw was found in the Tempo Operator. When the Jaeger UI Monitor Tab functionality is enabled in a Tempo instance managed by the Tempo Operator, the Operator creates a ClusterRoleBinding for the Service Account of the Tempo instance to grant the cluster-monitoring-view ClusterR

lownvdPublished 2025-04-02

CVE-2025-2842 CVSS: 4.3 MEDIUM Published: 2025-04-02T12:15:14.677

A flaw was found in the Tempo Operator. When the Jaeger UI Monitor Tab functionality is enabled in a Tempo instance managed by the Tempo Operator, the Operator creates a ClusterRoleBinding for the Service Account of the Tempo instance to grant the cluster-monitoring-view ClusterRole. This can be exploited if a user has 'create' per

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2025-2842