6.5
CVE-2026-62147
- EPSS 0.21%
- Veröffentlicht 13.07.2026 11:43:59
- Zuletzt bearbeitet 13.07.2026 17:01:11
- CVE-Watchlists
- Unerledigt
Tempo-operator: tempo operator: query rbac bypass
The Tempo Operator's gateway component failed to consistently apply namespace-scoped redaction on some query API response paths when query RBAC was enabled, allowing an authenticated user to read span attributes belonging to other tenants' namespaces.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerRed Hat
≫
Produkt
Red Hat OpenShift distributed tracing 3
Default Statusaffected
HerstellerRed Hat
≫
Produkt
Red Hat OpenShift distributed tracing 3
Default Statusaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.21% | 0.11 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| RedHat | 6.5 | 2.8 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
|
CWE-863 Incorrect Authorization
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
https://access.redhat.com/security/cve/CVE-2026-62147
https://bugzilla.redhat.com/show_bug.cgi?id=2499635