Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-62147

Опубликовано: 13 июл. 2026
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

The Tempo Operator's gateway component failed to consistently apply namespace-scoped redaction on some query API response paths when query RBAC was enabled, allowing an authenticated user to read span attributes belonging to other tenants' namespaces.

Отчет

This affects Red Hat OpenShift distributed tracing platform deployments with the Tempo Operator's query RBAC feature enabled prior to tempo-operator.v0.21.0-2, which corrects the gateway's authorization handling; the fix has already shipped to customers via RHSA-2026:33612.

Меры по смягчению последствий

There is no mitigation or workaround other than upgrading to tempo-operator.v0.21.0-2 (or later); until upgraded, administrators requiring strict namespace isolation of trace data should not rely on query RBAC alone and should consider restricting access to the Tempo query API at the network/route level as a temporary compensating control.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenShift distributed tracing 3rhosdt/tempo-operator-bundleFix deferred
Red Hat OpenShift distributed tracing 3rhosdt/tempo-rhel9-operatorFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-863
https://bugzilla.redhat.com/show_bug.cgi?id=2499635tempo-operator: Tempo Operator: Query RBAC bypass

EPSS

Процентиль: 11%
0.00209
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
nvd
21 день назад

The Tempo Operator's gateway component failed to consistently apply namespace-scoped redaction on some query API response paths when query RBAC was enabled, allowing an authenticated user to read span attributes belonging to other tenants' namespaces.

CVSS3: 6.5
github
21 день назад

The Tempo Operator's gateway component failed to consistently apply namespace-scoped redaction on some query API response paths when query RBAC was enabled, allowing an authenticated user to read span attributes belonging to other tenants' namespaces.

EPSS

Процентиль: 11%
0.00209
Низкий

6.5 Medium

CVSS3