Описание
Datadog dd-trace-go is a Go client library for Datadog application performance monitoring, profiling, and security monitoring. Prior to 2.8.1, Datadog tracing libraries that implement W3C baggage propagation parse incoming baggage HTTP headers without enforcing DD_TRACE_BAGGAGE_MAX_ITEMS or DD_TRACE_BAGGAGE_MAX_BYTES limits on the extract path. A remote, unauthenticated attacker can send a request whose baggage header contains an arbitrarily large number of comma-separated key-value pairs or a single very large value, causing unbounded CPU and memory consumption and enabling a remote denial of service against HTTP services with baggage propagation enabled. This issue is fixed in version 2.8.1.
A flaw was found in Datadog dd-trace-go, a Go client library. A remote, unauthenticated attacker can exploit this vulnerability by sending a request with a specially crafted baggage header containing an arbitrarily large number of key-value pairs or a very large single value. This can lead to unbounded CPU and memory consumption, resulting in a denial of service (DoS) against HTTP services that have baggage propagation enabled.
Отчет
Red Hat Advanced Cluster Management for Kubernetes and OpenShift Container Platform 4.21+ ship versions of the Datadog dd-trace-go v2 library prior to v2.8.1 that are vulnerable to this denial-of-service flaw in W3C baggage header parsing. OpenShift Container Platform 4.12 through 4.20 ships dd-trace-go v1, which does not implement W3C baggage propagation and is not affected.
Меры по смягчению последствий
If Datadog APM tracing with W3C baggage propagation is enabled, disable the baggage propagator by setting the DD_TRACE_PROPAGATION_STYLE environment variable to exclude 'baggage'.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Advanced Cluster Management for Kubernetes 2 | rhacm2/lighthouse-agent-rhel9 | Not affected | ||
| Red Hat Advanced Cluster Management for Kubernetes 2 | rhacm2/lighthouse-coredns-rhel9 | Affected | ||
| Red Hat OpenShift Container Platform 4 | openshift4/ose-coredns | Not affected | ||
| Red Hat OpenShift Container Platform 4 | openshift4/ose-coredns-rhel9 | Affected |
Показывать по
Ссылки на источники
Дополнительная информация
Статус:
7.5 High
CVSS3
Связанные уязвимости
Datadog dd-trace-go is a Go client library for Datadog application performance monitoring, profiling, and security monitoring. Prior to 2.8.1, Datadog tracing libraries that implement W3C baggage propagation parse incoming baggage HTTP headers without enforcing DD_TRACE_BAGGAGE_MAX_ITEMS or DD_TRACE_BAGGAGE_MAX_BYTES limits on the extract path. A remote, unauthenticated attacker can send a request whose baggage header contains an arbitrarily large number of comma-separated key-value pairs or a single very large value, causing unbounded CPU and memory consumption and enabling a remote denial of service against HTTP services with baggage propagation enabled. This issue is fixed in version 2.8.1.
dd-trace-go: Improper parsing of W3C baggage headers may lead to DoS
7.5 High
CVSS3