The Tempo Operator's gateway component failed to consistently apply namespace-scoped redaction on some query API response paths when query RBAC was enabled, allowing an authenticated user to read span attributes belonging to other tenants' namespaces.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-07-13 12:16
Updated : 2026-07-13 17:01
NVD link : CVE-2026-62147
Mitre link : CVE-2026-62147
CVE.ORG link : CVE-2026-62147
JSON object : View
Products Affected
No product.
CWE
CWE-863
Incorrect Authorization
