Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Red Hat Security Advisory: Red Hat OpenShift distributed tracing platform (Tempo) 3.5.1 release

0
High
Published: Fri Apr 04 2025 (04/04/2025, 13:38:55 UTC)
Source: GCVE Database
Vendor/Project: Red Hat Product Security
Product: Red Hat

Description

Red Hat OpenShift distributed tracing platform (Tempo) 3. 5. 1 includes security improvements and bug fixes addressing multiple vulnerabilities, including CVE-2025-2786. This update requires users to have specific permissions (TokenReview and SubjectAccessReview) to create or modify multi-tenant TempoStack or TempoMonolithic custom resources. A known issue exists where the gateway component's ServiceAccount needs these permissions when tenancy mode is enabled, with a recommended workaround involving deployment in a dedicated namespace and auditing user permissions. No explicit patch links are provided, but the advisory references the updated release and upgrade documentation.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 05/27/2026, 00:20:35 UTC

Technical Analysis

The Red Hat OpenShift distributed tracing platform (Tempo) 3.5.1 release incorporates security fixes for vulnerabilities such as CVE-2025-2786 and CVE-2025-2842. The update enforces stricter permission requirements for managing multi-tenancy configurations, specifically requiring TokenReview and SubjectAccessReview permissions. A known issue requires careful namespace isolation and permission auditing for the gateway component's ServiceAccount when tenancy mode is enabled. The release is based on Grafana Tempo 2.7.1 and includes no deprecations or technology preview features. No direct patch links are provided, but upgrade instructions are available in Red Hat's documentation.

Potential Impact

The vulnerabilities addressed are rated high severity and relate to improper authorization and information exposure issues (CWE-200, CWE-405). Without proper permissions, users could potentially create or modify multi-tenant tracing configurations improperly. The known issue with gateway ServiceAccount permissions could lead to authorization challenges if not mitigated. There are no known exploits in the wild at this time.

Mitigation Recommendations

Red Hat provides an updated release (Tempo 3.5.1) that includes fixes for the referenced CVEs. Users should upgrade to this version following Red Hat's official upgrade procedures documented in their OpenShift operator upgrade guides. For the known issue with tenancy mode, deploy Tempo instances in dedicated namespaces and audit user permissions carefully to restrict access to Secrets. The update requires users to have TokenReview and SubjectAccessReview permissions to manage multi-tenant resources, so ensure these permissions are granted appropriately. Patch status is not explicitly stated as a separate patch but is integrated into the 3.5.1 release; users should consult the vendor advisory and upgrade accordingly.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2025:3607
Cve Count
3
Additional Cves
["CVE-2025-2842","CVE-2025-30204"]
Cvss Version
null

Threat ID: 6a160973e29bf47b5063c532

Added to database: 5/26/2026, 8:58:27 PM

Last enriched: 5/27/2026, 12:20:35 AM

Last updated: 5/27/2026, 5:01:42 AM

Views: 2

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses