Description

A flaw was found in the Observability Operator. The Operator creates a ServiceAccount with *ClusterRole* upon deployment of the *Namespace-Scoped* Custom Resource MonitorStack. This issue allows an adversarial Kubernetes Account with only namespaced-level roles, for example, a tenant controlling a namespace, to create a MonitorStack in the authorized namespace and then elevate permission to the cluster level by impersonating the ServiceAccount created by the Operator, resulting in privilege escalation and other issues.

INFO

Published Date :

2025-11-12T16:36:04.735Z

Last Modified :

2025-12-19T18:30:24.732Z

Source :

redhat
AFFECTED PRODUCTS

The following products are affected by CVE-2025-2843 vulnerability.

Vendors Products
Redhat
  • Cluster Observability Operator

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact