Skip to main content
EPSS 0.3%top 73%

Red Hat Security Advisory: Red Hat OpenShift distributed tracing platform (Tempo) 3.4 release

0
Medium
Published: 12/11/2024 (12/11/2024, 11:11:24 UTC)
Source: GCVE Database
Vendor/Project: Red Hat Product Security
Product: Red Hat

Description

Red Hat OpenShift distributed tracing platform based on Tempo. Tempo is an open-source, easy-to-use, and highly scalable distributed tracing backend. It provides observability for microservices architectures by allowing developers to track requests as they flow through distributed systems. Tempo is optimized to handle large volumes of trace data and is designed to be highly performant even under heavy loads. - https://docs.redhat.com/en/documentation/openshift_container_platform/4.17 /html/distributed_tracing/distributed-tracing-platform-tempo

Affected software

Affected versions
>=3.4.0 <=3.4Red HatRed Hat OpenShift distributed tracingRed Hat OpenShift distributed tracing 3.4amd64registry.redhat.io/rhosdt/tempo-operator-bundle@sha256:a980e21c5cf96387bee07f2f271e73060bb5032ac969d678dc1f718841531ecb_amd64

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/16/2026, 17:03:13 UTC

Technical Analysis

CVE-2024-8260 is an authentication bypass vulnerability (CWE-294) in the Open Policy Agent (OPA) component used in Red Hat OpenShift distributed tracing platform (Tempo) 3.4. The flaw allows an attacker with local access to the OPA CLI or its Go library functions to pass an arbitrary SMB share instead of a Rego policy file, potentially triggering SMB force-authentication. This could lead to unauthorized access or manipulation of data if exploited. The attack vector is limited due to the requirement for local access and control over OPA CLI arguments. Red Hat classifies this vulnerability as moderate severity and currently does not provide a remediation that meets their standards for deployment and stability.

Potential Impact

If exploited, this vulnerability could allow an attacker with local access and control over OPA CLI arguments to force SMB authentication, potentially leading to unauthorized access or data manipulation. However, exploitation requires specific conditions, including direct access to the OPA CLI or Go library functions and the ability to influence input arguments, limiting the attack surface.

Mitigation Recommendations

Currently, there is no official fix or mitigation available that meets Red Hat Product Security criteria for ease of use, deployment, and applicability. Users should monitor Red Hat advisories for updates. Due to the limited attack vector, restricting local access to OPA CLI and careful control of input arguments can reduce risk. For detailed upgrade and operator management instructions, refer to Red Hat OpenShift documentation.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2024:10948
Cve Count
1

Threat ID: 6a5d27b02a4a8d5989132dc1

Added to database: 07/19/2026, 19:38:24 UTC

Last enriched: 08/16/2026, 17:03:13 UTC

Last updated: 09/10/2026, 19:36:49 UTC

Views: 37

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses