THREAT OPS › Threat News › [NVD] CVE-2025-2842 (MEDIUM 4.3) — A flaw was found in the Tempo Operator. When the Jaeger UI Monitor Tab functionality is enabled in a Tempo instance managed by the Tempo Operator, the Operator creates a ClusterRoleBinding for the Service Account of the Tempo instance to grant the cluster-monitoring-view ClusterR
[NVD] CVE-2025-2842 (MEDIUM 4.3) — A flaw was found in the Tempo Operator. When the Jaeger UI Monitor Tab functionality is enabled in a Tempo instance managed by the Tempo Operator, the Operator creates a ClusterRoleBinding for the Service Account of the Tempo instance to grant the cluster-monitoring-view ClusterR
CVE-2025-2842 CVSS: 4.3 MEDIUM Published: 2025-04-02T12:15:14.677
A flaw was found in the Tempo Operator. When the Jaeger UI Monitor Tab functionality is enabled in a Tempo instance managed by the Tempo Operator, the Operator creates a ClusterRoleBinding for the Service Account of the Tempo instance to grant the cluster-monitoring-view ClusterRole. This can be exploited if a user has 'create' per
Indicators of compromise
- CVE-2025-2842cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2025-2842