Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 14

Количество 14

ubuntu логотип

CVE-2023-47108

почти 3 года назад

OpenTelemetry-Go Contrib is a collection of third-party packages for OpenTelemetry-Go. Starting in version 0.37.0 and prior to version 0.46.0, the grpc Unary Server Interceptor out of the box adds labels `net.peer.sock.addr` and `net.peer.sock.port` that have unbound cardinality. It leads to the server's potential memory exhaustion when many malicious requests are sent. An attacker can easily flood the peer address and port for requests. Version 0.46.0 contains a fix for this issue. As a workaround to stop being affected, a view removing the attributes can be used. The other possibility is to disable grpc metrics instrumentation by passing `otelgrpc.WithMeterProvider` option with `noop.NewMeterProvider`.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2023-47108

почти 3 года назад

OpenTelemetry-Go Contrib is a collection of third-party packages for OpenTelemetry-Go. Starting in version 0.37.0 and prior to version 0.46.0, the grpc Unary Server Interceptor out of the box adds labels `net.peer.sock.addr` and `net.peer.sock.port` that have unbound cardinality. It leads to the server's potential memory exhaustion when many malicious requests are sent. An attacker can easily flood the peer address and port for requests. Version 0.46.0 contains a fix for this issue. As a workaround to stop being affected, a view removing the attributes can be used. The other possibility is to disable grpc metrics instrumentation by passing `otelgrpc.WithMeterProvider` option with `noop.NewMeterProvider`.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2023-47108

почти 3 года назад

OpenTelemetry-Go Contrib is a collection of third-party packages for OpenTelemetry-Go. Starting in version 0.37.0 and prior to version 0.46.0, the grpc Unary Server Interceptor out of the box adds labels `net.peer.sock.addr` and `net.peer.sock.port` that have unbound cardinality. It leads to the server's potential memory exhaustion when many malicious requests are sent. An attacker can easily flood the peer address and port for requests. Version 0.46.0 contains a fix for this issue. As a workaround to stop being affected, a view removing the attributes can be used. The other possibility is to disable grpc metrics instrumentation by passing `otelgrpc.WithMeterProvider` option with `noop.NewMeterProvider`.

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2023-47108

больше 2 лет назад

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-8pgv-569h-w5rw

почти 3 года назад

otelgrpc DoS vulnerability due to unbound cardinality metrics

CVSS3: 7.5
EPSS: Низкий
fstec логотип

BDU:2024-06663

почти 3 года назад

Уязвимость набора дополнительных инструментов и библиотек для языка Go, предназначенных для интеграции с OpenTelemetry, OpenTelemetry-Go Contrib, связанная с распределением ресурсов без ограничений и регулирования, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:4360-1

больше 1 года назад

Security update for docker

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:4319-1

больше 1 года назад

Security update for docker

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:3221-1

почти 2 года назад

Security update for containerd

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:3188-1

почти 2 года назад

Security update for containerd

EPSS: Низкий
redos логотип

ROS-20250801-01

около 1 года назад

Множественные уязвимости golang-opentelemetry-contrib-devel

CVSS3: 7.5
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2025:0003-1

больше 1 года назад

Security update for etcd

EPSS: Низкий
redos логотип

ROS-20240826-13

почти 2 года назад

Множественные уязвимости etcd

CVSS3: 7.5
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:3656-1

почти 2 года назад

Security update for etcd

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2023-47108

OpenTelemetry-Go Contrib is a collection of third-party packages for OpenTelemetry-Go. Starting in version 0.37.0 and prior to version 0.46.0, the grpc Unary Server Interceptor out of the box adds labels `net.peer.sock.addr` and `net.peer.sock.port` that have unbound cardinality. It leads to the server's potential memory exhaustion when many malicious requests are sent. An attacker can easily flood the peer address and port for requests. Version 0.46.0 contains a fix for this issue. As a workaround to stop being affected, a view removing the attributes can be used. The other possibility is to disable grpc metrics instrumentation by passing `otelgrpc.WithMeterProvider` option with `noop.NewMeterProvider`.

CVSS3: 7.5
2%
Низкий
почти 3 года назад
redhat логотип
CVE-2023-47108

OpenTelemetry-Go Contrib is a collection of third-party packages for OpenTelemetry-Go. Starting in version 0.37.0 and prior to version 0.46.0, the grpc Unary Server Interceptor out of the box adds labels `net.peer.sock.addr` and `net.peer.sock.port` that have unbound cardinality. It leads to the server's potential memory exhaustion when many malicious requests are sent. An attacker can easily flood the peer address and port for requests. Version 0.46.0 contains a fix for this issue. As a workaround to stop being affected, a view removing the attributes can be used. The other possibility is to disable grpc metrics instrumentation by passing `otelgrpc.WithMeterProvider` option with `noop.NewMeterProvider`.

CVSS3: 7.5
2%
Низкий
почти 3 года назад
nvd логотип
CVE-2023-47108

OpenTelemetry-Go Contrib is a collection of third-party packages for OpenTelemetry-Go. Starting in version 0.37.0 and prior to version 0.46.0, the grpc Unary Server Interceptor out of the box adds labels `net.peer.sock.addr` and `net.peer.sock.port` that have unbound cardinality. It leads to the server's potential memory exhaustion when many malicious requests are sent. An attacker can easily flood the peer address and port for requests. Version 0.46.0 contains a fix for this issue. As a workaround to stop being affected, a view removing the attributes can be used. The other possibility is to disable grpc metrics instrumentation by passing `otelgrpc.WithMeterProvider` option with `noop.NewMeterProvider`.

CVSS3: 7.5
2%
Низкий
почти 3 года назад
msrc логотип
CVSS3: 7.5
2%
Низкий
больше 2 лет назад
github логотип
GHSA-8pgv-569h-w5rw

otelgrpc DoS vulnerability due to unbound cardinality metrics

CVSS3: 7.5
2%
Низкий
почти 3 года назад
fstec логотип
BDU:2024-06663

Уязвимость набора дополнительных инструментов и библиотек для языка Go, предназначенных для интеграции с OpenTelemetry, OpenTelemetry-Go Contrib, связанная с распределением ресурсов без ограничений и регулирования, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
2%
Низкий
почти 3 года назад
suse-cvrf логотип
SUSE-SU-2024:4360-1

Security update for docker

больше 1 года назад
suse-cvrf логотип
SUSE-SU-2024:4319-1

Security update for docker

больше 1 года назад
suse-cvrf логотип
SUSE-SU-2024:3221-1

Security update for containerd

почти 2 года назад
suse-cvrf логотип
SUSE-SU-2024:3188-1

Security update for containerd

почти 2 года назад
redos логотип
ROS-20250801-01

Множественные уязвимости golang-opentelemetry-contrib-devel

CVSS3: 7.5
около 1 года назад
suse-cvrf логотип
openSUSE-SU-2025:0003-1

Security update for etcd

больше 1 года назад
redos логотип
ROS-20240826-13

Множественные уязвимости etcd

CVSS3: 7.5
почти 2 года назад
suse-cvrf логотип
SUSE-SU-2024:3656-1

Security update for etcd

почти 2 года назад

Уязвимостей на страницу