RHSA-2025:3740HighCVSS 7.5

Red Hat Security Advisory: Red Hat OpenShift distributed tracing platform (Tempo) 3.5.1 release

Published
April 9, 2025
Last Modified
August 26, 2026

🔗 CVE IDs covered (5)

📋 Description

CVE-2025-2786 — tempo-operator: ServiceAccount Token Exposure Leading to Token and Subject Access Reviews in OpenShift Tempo Operator CVE-2025-2842 — tempo-operator: Tempo Operator Token Exposition lead to read sensitive data CVE-2025-22868 — golang.org/x/oauth2/jws: Unexpected memory consumption during token parsing in golang.org/x/oauth2/jws CVE-2025-29786 — github.com/expr-lang/expr: Memory Exhaustion in Expr Parser with Unrestricted Input CVE-2025-30204 — golang-jwt/jwt: jwt-go allows excessive memory allocation during header parsing

🎯 Affected products26

  • Red Hat OpenShift distributed tracing 3.5.2
  • registry.redhat.io/rhosdt/tempo-gateway-opa-rhel8@sha256:0e311a7e92c0499a45eebbb07c6a96ae0ba15f4d9a598ca94ed67ac02dd3a724_arm64 as a component of Red Hat OpenShift distributed tracing 3.5.2
  • registry.redhat.io/rhosdt/tempo-gateway-opa-rhel8@sha256:1c9c288c2f2c50135c7b9827e7e5015e49f113b7db90e302f2cfc3081c547400_ppc64le as a component of Red Hat OpenShift distributed tracing 3.5.2
  • registry.redhat.io/rhosdt/tempo-gateway-opa-rhel8@sha256:1f26498b0fff3cd20e0049d3e3583f04c39ee2bdea12faf82daa5bf071afa4ad_s390x as a component of Red Hat OpenShift distributed tracing 3.5.2
  • registry.redhat.io/rhosdt/tempo-gateway-opa-rhel8@sha256:4d4311de1b860d6048d4f1bd6344176a1e1e1b9a3fa8e1ca9d079655b48ade14_amd64 as a component of Red Hat OpenShift distributed tracing 3.5.2
  • registry.redhat.io/rhosdt/tempo-gateway-rhel8@sha256:1fde0014b18d986d2167413da818ac03385ef7cec2d4c83b65f8b9c038e679d2_arm64 as a component of Red Hat OpenShift distributed tracing 3.5.2
  • registry.redhat.io/rhosdt/tempo-gateway-rhel8@sha256:49aa6055cf509b0de891bdf59e66a4c1e1e3536abedf0ca77537d4be86b4f9c9_s390x as a component of Red Hat OpenShift distributed tracing 3.5.2
  • registry.redhat.io/rhosdt/tempo-gateway-rhel8@sha256:9502242017d18e1d0b643a93e769b302a38799a9d719e703b64801d65e11dcd4_amd64 as a component of Red Hat OpenShift distributed tracing 3.5.2
  • registry.redhat.io/rhosdt/tempo-gateway-rhel8@sha256:af8c4ae92437cb495fe07e966bbf8654bd1e4a6c3684c7462c1e158c6fecd592_ppc64le as a component of Red Hat OpenShift distributed tracing 3.5.2
  • registry.redhat.io/rhosdt/tempo-jaeger-query-rhel8@sha256:21d649e446e04454767669f584518ac826af1b06d1c9fa7c8e2f6fd77c764f0a_arm64 as a component of Red Hat OpenShift distributed tracing 3.5.2
  • registry.redhat.io/rhosdt/tempo-jaeger-query-rhel8@sha256:3d712fb696afadcfe42ba48c563f39546c2ea7fe86837be969a57437849426ad_amd64 as a component of Red Hat OpenShift distributed tracing 3.5.2
  • registry.redhat.io/rhosdt/tempo-jaeger-query-rhel8@sha256:a365d4ea95d286955dbe3a7d939e8807d8d2fe0169ffaa1797ab5a86c0883143_s390x as a component of Red Hat OpenShift distributed tracing 3.5.2
  • registry.redhat.io/rhosdt/tempo-jaeger-query-rhel8@sha256:c36924a16868658ef60697ea670d97151d045af148d942d8ba18dcf94e468aa8_ppc64le as a component of Red Hat OpenShift distributed tracing 3.5.2
  • registry.redhat.io/rhosdt/tempo-operator-bundle@sha256:311f7152652df58705aeda77b9053e29f2333a146eb8f686db39938cb2c84f90_amd64 as a component of Red Hat OpenShift distributed tracing 3.5.2
  • registry.redhat.io/rhosdt/tempo-query-rhel8@sha256:3da15d796c2f1828a19021d908504810d461cb8b9f6901dad8a032e45f42c4c3_ppc64le as a component of Red Hat OpenShift distributed tracing 3.5.2
  • registry.redhat.io/rhosdt/tempo-query-rhel8@sha256:a453174d18447265ba7d7ee0ef9825688f474dada9be17b80246e0d0a0f5e042_arm64 as a component of Red Hat OpenShift distributed tracing 3.5.2
  • registry.redhat.io/rhosdt/tempo-query-rhel8@sha256:a78e6f74ac9e12b979b80c6965fffa647e103205b0b9ad8262ca3509f02a4f2b_amd64 as a component of Red Hat OpenShift distributed tracing 3.5.2
  • registry.redhat.io/rhosdt/tempo-query-rhel8@sha256:fd801d7d1cc2cd524c48ddc92afc7dbbac73f97e5e11e559396a975f24a979fe_s390x as a component of Red Hat OpenShift distributed tracing 3.5.2
  • registry.redhat.io/rhosdt/tempo-rhel8-operator@sha256:9f3e34f7d7f600ca57a2cfa2abc665a12b9170595de8f99ee36025e8f4311ea2_arm64 as a component of Red Hat OpenShift distributed tracing 3.5.2
  • registry.redhat.io/rhosdt/tempo-rhel8-operator@sha256:be2ec2e3d3b21748cfe3b9382f7fc1f6c72d5f380fc97773518c254c6e5794ca_amd64 as a component of Red Hat OpenShift distributed tracing 3.5.2
  • registry.redhat.io/rhosdt/tempo-rhel8-operator@sha256:d15d039fa5629a0a0c5abb6bced7aa635e9c5255913920232b02b1fb32c4e7fb_s390x as a component of Red Hat OpenShift distributed tracing 3.5.2
  • registry.redhat.io/rhosdt/tempo-rhel8-operator@sha256:e0e3273eceb8339638f2f1d91bb5eb6a57cfc0bc1442fcdea5fcff36812ccb4c_ppc64le as a component of Red Hat OpenShift distributed tracing 3.5.2
  • registry.redhat.io/rhosdt/tempo-rhel8@sha256:7a173206a8aca1d9f21cdbe1dfd87ed89953b573f3b9c2e7caa84e7d575bbba0_amd64 as a component of Red Hat OpenShift distributed tracing 3.5.2
  • registry.redhat.io/rhosdt/tempo-rhel8@sha256:7e06b1db99489d9059c09dafedda7f112598ee7bdecd53cf67bf36e910bde271_s390x as a component of Red Hat OpenShift distributed tracing 3.5.2
  • registry.redhat.io/rhosdt/tempo-rhel8@sha256:948a4c3788e7e9135510af743bde8751ccf10ae9edd5452db48da6b558606c5f_arm64 as a component of Red Hat OpenShift distributed tracing 3.5.2
  • registry.redhat.io/rhosdt/tempo-rhel8@sha256:d0e7bae0605cb69b34347e9c0d07314842c19bef22b413e1fba9aa2aa2e98675_ppc64le as a component of Red Hat OpenShift distributed tracing 3.5.2

✅ Remediation

For details on how to apply this update, refer to: https://docs.redhat.com/en/documentation/openshift_container_platform/latest/html/operators/administrator-tasks#olm-upgrading-operators Workaround: Currently, no mitigation is available for this vulnerability. Workaround: To mitigate this vulnerability, it is recommended to pre-validate any payloads passed to `go-jose` to check that they do not contain an excessive amount of `.` characters. Workaround: To mitigate this vulnerability, it is recommended to impose an input size restriction before parsing (i.e. validating or limiting the length of expression strings that the application will accept). Ensuring no unbounded-length expressions are fed into the parser will prevent the parser from constructing a very large AST and avoid the potential memory exhaustion issue. Workaround: Red Hat Product Security does not have a recommended mitigation at this time.

🔗 References (9)