Red Hat Security Advisory: Red Hat OpenShift distributed tracing platform (Tempo) 3.5.1 release
Red Hat OpenShift distributed tracing platform (Tempo) 3. 5. 1 includes security improvements and bug fixes addressing multiple vulnerabilities, including CVE-2025-2786. This update requires users to have specific permissions (TokenReview and SubjectAccessReview) to create or modify multi-tenant TempoStack or TempoMonolithic custom resources. A known issue exists where the gateway component's ServiceAccount needs these permissions when tenancy mode is enabled, with a recommended workaround involving deployment in a dedicated namespace and auditing user permissions. No explicit patch links are provided, but the advisory references the updated release and upgrade documentation.
AI Analysis
Technical Summary
The Red Hat OpenShift distributed tracing platform (Tempo) 3.5.1 release incorporates security fixes for vulnerabilities such as CVE-2025-2786 and CVE-2025-2842. The update enforces stricter permission requirements for managing multi-tenancy configurations, specifically requiring TokenReview and SubjectAccessReview permissions. A known issue requires careful namespace isolation and permission auditing for the gateway component's ServiceAccount when tenancy mode is enabled. The release is based on Grafana Tempo 2.7.1 and includes no deprecations or technology preview features. No direct patch links are provided, but upgrade instructions are available in Red Hat's documentation.
Potential Impact
The vulnerabilities addressed are rated high severity and relate to improper authorization and information exposure issues (CWE-200, CWE-405). Without proper permissions, users could potentially create or modify multi-tenant tracing configurations improperly. The known issue with gateway ServiceAccount permissions could lead to authorization challenges if not mitigated. There are no known exploits in the wild at this time.
Mitigation Recommendations
Red Hat provides an updated release (Tempo 3.5.1) that includes fixes for the referenced CVEs. Users should upgrade to this version following Red Hat's official upgrade procedures documented in their OpenShift operator upgrade guides. For the known issue with tenancy mode, deploy Tempo instances in dedicated namespaces and audit user permissions carefully to restrict access to Secrets. The update requires users to have TokenReview and SubjectAccessReview permissions to manage multi-tenant resources, so ensure these permissions are granted appropriately. Patch status is not explicitly stated as a separate patch but is integrated into the 3.5.1 release; users should consult the vendor advisory and upgrade accordingly.
Red Hat Security Advisory: Red Hat OpenShift distributed tracing platform (Tempo) 3.5.1 release
Description
Red Hat OpenShift distributed tracing platform (Tempo) 3. 5. 1 includes security improvements and bug fixes addressing multiple vulnerabilities, including CVE-2025-2786. This update requires users to have specific permissions (TokenReview and SubjectAccessReview) to create or modify multi-tenant TempoStack or TempoMonolithic custom resources. A known issue exists where the gateway component's ServiceAccount needs these permissions when tenancy mode is enabled, with a recommended workaround involving deployment in a dedicated namespace and auditing user permissions. No explicit patch links are provided, but the advisory references the updated release and upgrade documentation.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Red Hat OpenShift distributed tracing platform (Tempo) 3.5.1 release incorporates security fixes for vulnerabilities such as CVE-2025-2786 and CVE-2025-2842. The update enforces stricter permission requirements for managing multi-tenancy configurations, specifically requiring TokenReview and SubjectAccessReview permissions. A known issue requires careful namespace isolation and permission auditing for the gateway component's ServiceAccount when tenancy mode is enabled. The release is based on Grafana Tempo 2.7.1 and includes no deprecations or technology preview features. No direct patch links are provided, but upgrade instructions are available in Red Hat's documentation.
Potential Impact
The vulnerabilities addressed are rated high severity and relate to improper authorization and information exposure issues (CWE-200, CWE-405). Without proper permissions, users could potentially create or modify multi-tenant tracing configurations improperly. The known issue with gateway ServiceAccount permissions could lead to authorization challenges if not mitigated. There are no known exploits in the wild at this time.
Mitigation Recommendations
Red Hat provides an updated release (Tempo 3.5.1) that includes fixes for the referenced CVEs. Users should upgrade to this version following Red Hat's official upgrade procedures documented in their OpenShift operator upgrade guides. For the known issue with tenancy mode, deploy Tempo instances in dedicated namespaces and audit user permissions carefully to restrict access to Secrets. The update requires users to have TokenReview and SubjectAccessReview permissions to manage multi-tenant resources, so ensure these permissions are granted appropriately. Patch status is not explicitly stated as a separate patch but is integrated into the 3.5.1 release; users should consult the vendor advisory and upgrade accordingly.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHSA-2025:3607
- Cve Count
- 3
- Additional Cves
- ["CVE-2025-2842","CVE-2025-30204"]
- Cvss Version
- null
Threat ID: 6a160973e29bf47b5063c532
Added to database: 5/26/2026, 8:58:27 PM
Last enriched: 5/27/2026, 12:20:35 AM
Last updated: 5/27/2026, 5:01:42 AM
Views: 2
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.