Описание
OpenTelemetry-Go is the Go implementation of OpenTelemetry. The OpenTelemetry Go SDK in version v1.20.0-1.39.0 is vulnerable to Path Hijacking (Untrusted Search Paths) on macOS/Darwin systems. The resource detection code in sdk/resource/host_id.go executes the ioreg system command using a search path. An attacker with the ability to locally modify the PATH environment variable can achieve Arbitrary Code Execution (ACE) within the context of the application. A fix was released with v1.40.0.
A flaw was found in OpenTelemetry-Go. On macOS/Darwin systems, the OpenTelemetry Go SDK is vulnerable to path hijacking, also known as untrusted search paths. A local attacker with the ability to modify the system's PATH environment variable could exploit this by injecting malicious code. This could lead to arbitrary code execution within the context of the application.
Отчет
Red Hat Workload Availability Operators FAR (fence-agents-remediation) and SBR (storage-based-remediation) bundle go.opentelemetry.io/otel/sdk in the vulnerable range (>=1.21.0, <1.40.0) prior to the rhwa-4.22-1 patch release. Fixed by bumping to v1.44.0 in the far-0.8.1 and sbr-0.3.1 streams. This flaw was previously auto-rejected (not found in Red Hat SBOM index at the time); reopened 2026-08-11 based on confirmed engineering source (dependency bump commits: FAR #211, SBR #80).
Меры по смягчению последствий
No customer action required for FAR/SBR as deployed on OpenShift: the vulnerable resource-detection code path only executes on macOS/Darwin hosts via the 'ioreg' command, which is never invoked on Red Hat's Linux container images. Fixed proactively via dependency bump to go.opentelemetry.io/otel/sdk v1.44.0 in far-0.8.1 and sbr-0.3.1.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Fence Agents Remediation Operator | redhat-user-workloads/far-operator-0-8 | Affected | ||
| Storage-Based Remediation | redhat-user-workloads/sbr-operator-0-3 | Affected |
Показывать по
Ссылки на источники
Дополнительная информация
Статус:
EPSS
7 High
CVSS3
Связанные уязвимости
OpenTelemetry-Go is the Go implementation of OpenTelemetry. The OpenTelemetry Go SDK in version v1.20.0-1.39.0 is vulnerable to Path Hijacking (Untrusted Search Paths) on macOS/Darwin systems. The resource detection code in sdk/resource/host_id.go executes the ioreg system command using a search path. An attacker with the ability to locally modify the PATH environment variable can achieve Arbitrary Code Execution (ACE) within the context of the application. A fix was released with v1.40.0.
OpenTelemetry-Go is the Go implementation of OpenTelemetry. The OpenTelemetry Go SDK in version v1.20.0-1.39.0 is vulnerable to Path Hijacking (Untrusted Search Paths) on macOS/Darwin systems. The resource detection code in sdk/resource/host_id.go executes the ioreg system command using a search path. An attacker with the ability to locally modify the PATH environment variable can achieve Arbitrary Code Execution (ACE) within the context of the application. A fix was released with v1.40.0.
OpenTelemetry-Go Affected by Arbitrary Code Execution via PATH Hijacking
OpenTelemetry-Go is the Go implementation of OpenTelemetry. The OpenTe ...
EPSS
7 High
CVSS3