Beveiligingsadvies

CVE-2026-62147

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-07-13 11:43:59
Laatst bijgewerkt 2026-07-13 13:43:50
Toegewezen door redhat
CVSS-score 6.5
Status PUBLISHED

Beschrijving

The Tempo Operator's gateway component failed to consistently apply namespace-scoped redaction on some query API response paths when query RBAC was enabled, allowing an authenticated user to read span attributes belonging to other tenants' namespaces.