Impact
The OpenTelemetry Operator is a Kubernetes Operator for the OpenTelemetry Collector. Prior to version 0.152.0, TargetAllocator instances with prometheusCR.enabled set to true treat a ServiceMonitor’s bearerTokenFile field as an HTTPClientConfig.Authorization.CredentialsFile that is read during each scrape. A tenant with the ability to create or update a ServiceMonitor that matches the operator’s serviceMonitorSelector and serviceMonitorNamespaceSelector can point bearerTokenFile to any file inside the Collector pod, such as the default service‑account token at /var/run/secrets/kubernetes.io/serviceaccount/token, and have the Collector send that file’s contents as a bearer token on every scrape to a tenant‑controlled endpoint. Exploitation requires that the referenced file be mounted inside the Collector pod and that the Collector can reach the chosen target. This flaw permits disclosure of sensitive local files, including the Collector’s service‑account JWT or other mounted‑200 information‑ex.
Affected Systems
The vulnerability affects all deployments of the OpenTelemetry Operator running a version earlier than 0.152.0 when targetAllocator.prometheusCR.enabled is set to true. Any tenant who can create or update a ServiceMonitor that matches the configured serviceMonitorSelector and serviceMonitorNamespaceSelector can exploit the flaw. The issue is tied to open-telemetry:opentelemetry-operator and upgrading to 0.152.0 or later removes the vulnerability.
Risk and Exploitability
The flaw can be leveraged by an attacker with permission to create or update ServiceMonitor resources in the Kubernetes API. The attacker can point the bearerTokenFile to an arbitrary file inside the Collector pod, causing the Collector to read that file and transmit its contents as a bearer token during each scrape interval. The CVSS score is 7.7, the EPSS score is less than 1%, and the issue is not listed in the CISA KEV catalog. While the leak is limited to the permissions of the Collector’s service account, the unauthorized exposure of the service‑account JWT or other secrets poses a significant risk in multi‑tenant environments with insufficient isolation.
OpenCVE Enrichment
Github GHSA