Grafana tempo是Grafana公司开源的一个分布式追踪后端服务。 Grafana tempo存在授权问题漏洞,该漏洞源于Tempo Operator的gateway组件在启用查询RBAC时未能一致地对某些查询API响应路径应用命名空间范围修饰,允许经身份验证的用户读取属于其他租户命名空间的span属性。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Red Hat | Red Hat OpenShift distributed tracing 3 | any |
affected |
any |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat OpenShift distributed tracing 3 | - |
cpe:/a:redhat:openshift_distributed_tracing:3
|
|
| Red Hat | Red Hat OpenShift distributed tracing 3 | - |
cpe:/a:redhat:openshift_distributed_tracing:3
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-15584 | 7.5 HIGH | Redhatinsights/incluster-checks: incluster-checks: privileged host-chroot debug pods creat |
| CVE-2026-15574 | 7.5 HIGH | Vllm-orchestrator-gateway: vllm-orchestrator-gateway: authorization header and full chat p |
No comments yet