CVE-2025-2786
A flaw was found in Tempo Operator, where it creates a ServiceAccount, ClusterRole, and ClusterRoleBinding when a user deploys a TempoStack or TempoMonolithic instance. This flaw allows a user with full access to their namespace to extract the ServiceAccount token and use it to submit TokenReview and SubjectAccessReview requests, potentially revealing information about other users' permissions. While this does not allow privilege escalation or impersonation, it exposes information that could aid in gathering information for further attacks.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- Puntuación base: 4.3
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.37%
- Percentil entre todas las CVEs puntuadas: 28
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
CWE
- CWE-200
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2025-2786",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2025-2786",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2025-04-02T13:53:24.818603Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "secalert@redhat.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 4.3,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "LOW",
"confidentialityImpact": "LOW"
},
"impactScore": 1.4,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "secalert@redhat.com",
"affectedData": [
{
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "0.15.3",
"versionType": "semver"
}
],
"packageName": "tempo-operator",
"collectionURL": "https://github.com/grafana/tempo-operator",
"defaultStatus": "unaffected"
},
{
"cpes": [
"cpe:/a:redhat:openshift_distributed_tracing:3.5::el8"
],
"vendor": "Red Hat",
"product": "Red Hat OpenShift distributed tracing 3.5.3",
"versions": [
{
"status": "unaffected",
"version": "rhosdt-3.5-1743162265",
"lessThan": "*",
"versionType": "rpm"
}
],
"packageName": "rhosdt/tempo-rhel8-operator",
"collectionURL": "https://catalog.redhat.com/software/containers/",
"defaultStatus": "affected"
},
{
"cpes": [
"cpe:/a:redhat:openshift_distributed_tracing:3.5::el8"
],
"vendor": "Red Hat",
"product": "Red Hat OpenShift distributed tracing 3.5.3",
"versions": [
{
"status": "unaffected",
"version": "rhosdt-3.5-1744028971",
"lessThan": "*",
"versionType": "rpm"
}
],
"packageName": "rhosdt/tempo-rhel8-operator",
"collectionURL": "https://catalog.redhat.com/software/containers/",
"defaultStatus": "affected"
},
{
"cpes": [
"cpe:/a:redhat:openshift_distributed_tracing:3"
],
"vendor": "Red Hat",
"product": "Red Hat OpenShift distributed tracing 3",
"packageName": "rhosdt/tempo-gateway-opa-rhel8",
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"defaultStatus": "affected"
},
{
"cpes": [
"cpe:/a:redhat:openshift_distributed_tracing:3"
],
"vendor": "Red Hat",
"product": "Red Hat OpenShift distributed tracing 3",
"packageName": "rhosdt/tempo-gateway-rhel8",
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"defaultStatus": "affected"
},
{
"cpes": [
"cpe:/a:redhat:openshift_distributed_tracing:3"
],
"vendor": "Red Hat",
"product": "Red Hat OpenShift distributed tracing 3",
"packageName": "rhosdt/tempo-jaeger-query-rhel8",
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"defaultStatus": "affected"
},
{
"cpes": [
"cpe:/a:redhat:openshift_distributed_tracing:3"
],
"vendor": "Red Hat",
"product": "Red Hat OpenShift distributed tracing 3",
"packageName": "rhosdt/tempo-query-rhel8",
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"defaultStatus": "affected"
},
{
"cpes": [
"cpe:/a:redhat:openshift_distributed_tracing:3"
],
"vendor": "Red Hat",
"product": "Red Hat OpenShift distributed tracing 3",
"packageName": "rhosdt/tempo-rhel8",
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"defaultStatus": "affected"
}
]
}
],
"published": "2025-04-02T11:15:39.300",
"references": [
{
"url": "https://access.redhat.com/errata/RHSA-2025:3607",
"source": "secalert@redhat.com"
},
{
"url": "https://access.redhat.com/errata/RHSA-2025:3740",
"source": "secalert@redhat.com"
},
{
"url": "https://access.redhat.com/security/cve/CVE-2025-2786",
"source": "secalert@redhat.com"
},
{
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2354811",
"source": "secalert@redhat.com"
},
{
"url": "https://github.com/grafana/tempo-operator/pull/1145",
"source": "secalert@redhat.com"
}
],
"vulnStatus": "Deferred",
"weaknesses": [
{
"type": "Secondary",
"source": "secalert@redhat.com",
"description": [
{
"lang": "en",
"value": "CWE-200"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "A flaw was found in Tempo Operator, where it creates a ServiceAccount, ClusterRole, and ClusterRoleBinding when a user deploys a TempoStack or TempoMonolithic instance. This flaw allows a user with full access to their namespace to extract the ServiceAccount token and use it to submit TokenReview and SubjectAccessReview requests, potentially revealing information about other users' permissions. While this does not allow privilege escalation or impersonation, it exposes information that could aid in gathering information for further attacks."
},
{
"lang": "es",
"value": "Se detectó una falla en Tempo Operator, que crea una cuenta de servicio, un rol de clúster y un enlace de rol de clúster cuando un usuario implementa una instancia de TempoStack o TempoMonolithic. Esta falla permite a un usuario con acceso completo a su espacio de nombres extraer el token de la cuenta de servicio y usarlo para enviar solicitudes TokenReview y SubjectAccessReview, lo que podría revelar información sobre los permisos de otros usuarios. Si bien esto no permite la escalada de privilegios ni la suplantación de identidad, expone información que podría facilitar la recopilación de información para futuros ataques."
}
],
"lastModified": "2026-09-08T22:17:36.290",
"sourceIdentifier": "secalert@redhat.com"
}