Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-62147

Опубликовано: 13 июл. 2026
Источник: nvd
CVSS3: 6.5
EPSS Низкий

Описание

The Tempo Operator's gateway component failed to consistently apply namespace-scoped redaction on some query API response paths when query RBAC was enabled, allowing an authenticated user to read span attributes belonging to other tenants' namespaces.

EPSS

Процентиль: 11%
0.00209
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-863

Связанные уязвимости

CVSS3: 6.5
redhat
21 день назад

The Tempo Operator's gateway component failed to consistently apply namespace-scoped redaction on some query API response paths when query RBAC was enabled, allowing an authenticated user to read span attributes belonging to other tenants' namespaces.

CVSS3: 6.5
github
21 день назад

The Tempo Operator's gateway component failed to consistently apply namespace-scoped redaction on some query API response paths when query RBAC was enabled, allowing an authenticated user to read span attributes belonging to other tenants' namespaces.

EPSS

Процентиль: 11%
0.00209
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-863