Executive brief
A security flaw was found in the Tempo Operator, a component used for distributed tracing in cloud environments to help monitor application performance. When specific access controls are enabled, an authorized user can bypass security restrictions to view sensitive trace data belonging to other teams or departments. This could lead to the unauthorized exposure of internal application metadata and span attributes across different organizational namespaces.
Technical details
An incorrect authorization flaw (CWE-863) exists in the Tempo Operator's gateway component when query RBAC is enabled. The vulnerability is rooted in the failure to consistently apply namespace-scoped redaction across all query API response paths. An attacker with low-privileged authenticated access to at least one namespace can craft queries that bypass redaction logic to retrieve span attributes from other tenants' namespaces. This is a network-based attack requiring no user interaction, impacting the confidentiality of distributed tracing data within Red Hat OpenShift environments.
Affected products
- Red Hat OpenShift distributed tracing 3 3
- Red Hat tempo-operator-bundle 3
- Red Hat tempo-rhel9-operator 3
Timeline
- 2026-07-13: disclosed: Initial report in Red Hat Bugzilla and NVD publication.