VDB

CVE-2025-2843

CVE-2025-2843 PUBLISHED CVSS 8.800000190734863 HIGH

A flaw was found in the Observability Operator. The Operator creates a ServiceAccount with *ClusterRole* upon deployment of the *Namespace-Scoped* Custom Resource MonitorStack. This issue allows an adversarial Kubernetes Account with only namespaced-level roles, for example, a tenant controlling a namespace, to create a MonitorStack in the authorized namespace and then elevate permission to the cluster level by impersonating the ServiceAccount created by the Operator, resulting in privilege escalation and other issues.

EPSS 0.05% · 16.8th percentile

Risk Scores

CVSS v3.1
8.800000190734863
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score
0.05%
16.8th percentile

Affected Products

VendorProductVersions
Red HatCluster Observability Operator 1.3.1sha256:84a281b3cd370cd42b89489c770f8b31d13e9aa570dc1b6cda6042bfba4824f8
github.comrhobs/observability-operator0
rhobsobservability-operator0

Timeline

  • Nov 12, 2025 CVE Published
  • Nov 12, 2025 Coalition ESS Score
  • Nov 12, 2025 PoC Published
  • Nov 12, 2025 PoC Published
  • Nov 12, 2025 PoC Published
  • Nov 13, 2025 EPSS Score
  • Nov 14, 2025 CVE Updated
  • Nov 16, 2025 Coalition ESS Score
  • Nov 18, 2025 EPSS Score
  • Nov 18, 2025 Coalition ESS Score
  • Nov 23, 2025 EPSS Score
  • Nov 26, 2025 Coalition ESS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›