Описание
The Tempo Operator's gateway component failed to consistently apply namespace-scoped redaction on some query API response paths when query RBAC was enabled, allowing an authenticated user to read span attributes belonging to other tenants' namespaces.
Отчет
This affects Red Hat OpenShift distributed tracing platform deployments with the Tempo Operator's query RBAC feature enabled prior to tempo-operator.v0.21.0-2, which corrects the gateway's authorization handling; the fix has already shipped to customers via RHSA-2026:33612.
Меры по смягчению последствий
There is no mitigation or workaround other than upgrading to tempo-operator.v0.21.0-2 (or later); until upgraded, administrators requiring strict namespace isolation of trace data should not rely on query RBAC alone and should consider restricting access to the Tempo query API at the network/route level as a temporary compensating control.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat OpenShift distributed tracing 3 | rhosdt/tempo-operator-bundle | Fix deferred | ||
| Red Hat OpenShift distributed tracing 3 | rhosdt/tempo-rhel9-operator | Fix deferred |
Показывать по
Дополнительная информация
Статус:
EPSS
6.5 Medium
CVSS3
Связанные уязвимости
The Tempo Operator's gateway component failed to consistently apply namespace-scoped redaction on some query API response paths when query RBAC was enabled, allowing an authenticated user to read span attributes belonging to other tenants' namespaces.
The Tempo Operator's gateway component failed to consistently apply namespace-scoped redaction on some query API response paths when query RBAC was enabled, allowing an authenticated user to read span attributes belonging to other tenants' namespaces.
EPSS
6.5 Medium
CVSS3