Impact
The Tempo Operator’s gateway component fails to apply namespace‑scoped redaction to certain query API responses when query RBAC is enabled, allowing an authenticated user to read span attributes that belong to other tenants. This authorization bypass (CWE‑863) exposes telemetry data to users who should not have access, thereby compromising tenant isolation and potentially revealing sensitive operational metrics.
Affected Systems
Red Hat OpenShift distributed tracing 3 is affected. All released versions prior to tempo‑operator v0.21.0‑2 are vulnerable; the issue is patched in that release and later versions.
Risk and Exploitability
The CVSS score of 6.5 indicates a medium severity vulnerability. The EPSS score of less than 1% signals a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector requires an authenticated user with RBAC permissions to issue query‑API requests; by sending specially crafted queries an attacker can retrieve span attributes from namespaces they are not authorized to view.
OpenCVE Enrichment