- Issued:
- 2024-12-11
- Updated:
- 2025-03-25
RHSA-2024:10948 - Security Advisory
Synopsis
Red Hat OpenShift distributed tracing platform (Tempo) 3.4 release
Type/Severity
Security Advisory: Moderate
Topic
A new version of Red Hat OpenShift distributed tracing platform (Tempo) has been released
Description
Red Hat OpenShift distributed tracing platform based on Tempo. Tempo is an open-source, easy-to-use, and highly scalable distributed tracing backend. It provides observability for microservices architectures by allowing developers to track requests as they flow through distributed systems. Tempo is optimized to handle large volumes of trace data and is designed to be highly performant even under heavy loads.
- https://docs.redhat.com/en/documentation/openshift_container_platform/4.17 /html/distributed_tracing/distributed-tracing-platform-tempo
Solution
For details on how to apply this update, refer to:
https://docs.redhat.com/en/documentation/openshift_container_platform/4.17/h tml/operators/administrator-tasks#olm-upgrading-operators
Affected Products
- Red Hat OpenShift distributed tracing
Fixes
- https://issues.redhat.com/browse/TRACING-4933 - Hitting F5 in the monitor tab of Jaeger UI results in a 404 when using the gateway
- https://issues.redhat.com/browse/TRACING-4932 - Enabling .spec.observability.tracing results in a crashloop of tempo-gateway-opa
- https://issues.redhat.com/browse/TRACING-4840 - OpenShift Console doesn't show the "" value for the spec.template.queryFrontend.jaegerQuery.ingress.type
- https://issues.redhat.com/browse/TRACING-4757 - Cannot scrape Tempo query frontend metrics endpoint if non-multitenant TempoStack is created.
- https://issues.redhat.com/browse/TRACING-4568 - Tempo and OpenTelemetry documentation for must-gather
- https://issues.redhat.com/browse/TRACING-4566 - Must gather for OpenTelemetry and Tempo Operators
- https://issues.redhat.com/browse/TRACING-4559 - Documentation improvement to include details for replicationFactor
- https://issues.redhat.com/browse/TRACING-4511 - Tempo: Jaeger UI queries fail with a 504 Gateway Time-out depending on result size and number of traces sent to TempoStack.
- https://issues.redhat.com/browse/TRACING-4507 - Failed to create memberlist ("no private IP address found") on TempoStack
- https://issues.redhat.com/browse/TRACING-4183 - FIPS compliance in Tempo
- https://issues.redhat.com/browse/TRACING-3545 - RHOSDT 2.9 Tempo 2.1.1 does not work on IBM Z (s390x) architecture
CVEs
amd64
| registry.redhat.io/rhosdt/tempo-operator-bundle@sha256:a980e21c5cf96387bee07f2f271e73060bb5032ac969d678dc1f718841531ecb |
| registry.redhat.io/rhosdt/tempo-gateway-rhel8@sha256:2f1053d920b634c03adf787bac07d0db0fbb4e13357ce979902baeb2ff733b90 |
| registry.redhat.io/rhosdt/tempo-jaeger-query-rhel8@sha256:7ceea9e3ce08b9a5f0de4365e1a17e5cefe3af093f007c0ccf8b026772adcac8 |
| registry.redhat.io/rhosdt/tempo-gateway-opa-rhel8@sha256:878871eb4c91180b2c4633ad7c40d0800349c665fe0c708e5c2e0e1f8d35c48c |
| registry.redhat.io/rhosdt/tempo-rhel8-operator@sha256:16785eee630f86dc75a04c1d5dd8ece16d6420cb63f1e1796ef77adcbf8662ff |
| registry.redhat.io/rhosdt/tempo-query-rhel8@sha256:3909b942c71db863fbc481af0af40f3240c9971e15eaf85bee91cc9c65ac25a8 |
| registry.redhat.io/rhosdt/tempo-rhel8@sha256:98440fdde03e04959fb1bdf157d8ccbe0d0dcf203d4424ad3964e2aebc44feac |
arm64
| registry.redhat.io/rhosdt/tempo-gateway-rhel8@sha256:1640c44f165db87d174d81ad44517bd76218e4611aa6ea5c717244d4483796c4 |
| registry.redhat.io/rhosdt/tempo-jaeger-query-rhel8@sha256:7470820932e792733adb52ff7360b2013e797d91ef0bdc9f363f9b2ae6b8f26c |
| registry.redhat.io/rhosdt/tempo-gateway-opa-rhel8@sha256:08b32341cc141f5151497b2c8a321b19dc6e666004bd72f32d5900c7874da794 |
| registry.redhat.io/rhosdt/tempo-rhel8-operator@sha256:a7a52669ccbb713b6e1c490b3ac4a34384bca1e2b37a7e7b9027763641977f12 |
| registry.redhat.io/rhosdt/tempo-query-rhel8@sha256:0def8c260423b78d00003438539c0fd4d67312a52c12ec8e255df953c101b782 |
| registry.redhat.io/rhosdt/tempo-rhel8@sha256:4d301062f6bac47d758ee27b4863dc32bfeb94af8f79b22c72bfc186e6303c73 |
ppc64le
| registry.redhat.io/rhosdt/tempo-gateway-rhel8@sha256:5a260f0177ba665c6398b22c2f0cd86689fe86e98e7379f48eb711c8318775d8 |
| registry.redhat.io/rhosdt/tempo-jaeger-query-rhel8@sha256:df35e34b9ffed7903fba071e2a98e0da58e731cee69023745da5abbc670dc14c |
| registry.redhat.io/rhosdt/tempo-gateway-opa-rhel8@sha256:7d31db98b11b155b16b355342bfa2963f6bb7481738e02e4bdcf00e43d48f0a2 |
| registry.redhat.io/rhosdt/tempo-rhel8-operator@sha256:e253ee88974b1b7369cccd809c00c5cb0e9f57a277858072637e009a427f8d50 |
| registry.redhat.io/rhosdt/tempo-query-rhel8@sha256:2a3af1845a046f2442de636e19fb34b8879492591a09097eddc228a3b283e166 |
| registry.redhat.io/rhosdt/tempo-rhel8@sha256:0fc7d7de882de2669d46e89801647587ac7ef1ea7e5573740b6b16371e5d76de |
s390x
| registry.redhat.io/rhosdt/tempo-gateway-rhel8@sha256:af6ac3d39a420bc4d12b5214b5b34fdbfd60484409ac08e83d6e33ec3724c528 |
| registry.redhat.io/rhosdt/tempo-jaeger-query-rhel8@sha256:09973f99b7d1f6804d11afbbb4748810d0b2b4aaca373b419d1da2150828cecb |
| registry.redhat.io/rhosdt/tempo-gateway-opa-rhel8@sha256:831bc3d120a4998eb256c44aa54887add11cceb817cf6a105733cfd828f58c5c |
| registry.redhat.io/rhosdt/tempo-rhel8-operator@sha256:a170105e1ef1791968db593603aefba6492b3ac50aa90bbff0075b767602038c |
| registry.redhat.io/rhosdt/tempo-query-rhel8@sha256:993b70c4740b88d399a0c68187adb9d0763492dede603d7989b7222f8fd5b185 |
| registry.redhat.io/rhosdt/tempo-rhel8@sha256:f5fa1289dcd26c961b6976d196eb800dedba7655a6545a697fc1ebe3dcb3517c |
The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.