Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 4

Количество 4

redhat логотип

CVE-2024-36129

больше 2 лет назад

The OpenTelemetry Collector offers a vendor-agnostic implementation on how to receive, process and export telemetry data. An unsafe decompression vulnerability allows unauthenticated attackers to crash the collector via excessive memory consumption. OTel Collector version 0.102.1 fixes this issue. It is also fixed in the confighttp module version 0.102.0 and configgrpc module version 0.102.1.

CVSS3: 8.2
EPSS: Низкий
nvd логотип

CVE-2024-36129

больше 2 лет назад

The OpenTelemetry Collector offers a vendor-agnostic implementation on how to receive, process and export telemetry data. An unsafe decompression vulnerability allows unauthenticated attackers to crash the collector via excessive memory consumption. OTel Collector version 0.102.1 fixes this issue. It is also fixed in the confighttp module version 0.102.0 and configgrpc module version 0.102.1.

CVSS3: 8.2
EPSS: Низкий
github логотип

GHSA-c74f-6mfw-mm4v

больше 2 лет назад

Denial of Service via Zip/Decompression Bomb sent over HTTP or gRPC

CVSS3: 8.2
EPSS: Низкий
fstec логотип

BDU:2024-05114

больше 2 лет назад

Уязвимость модулей confighttp и configgrpc программного обеспечения обработки данных телеметрии OpenTelemetry Collector, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 8.2
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2024-36129

The OpenTelemetry Collector offers a vendor-agnostic implementation on how to receive, process and export telemetry data. An unsafe decompression vulnerability allows unauthenticated attackers to crash the collector via excessive memory consumption. OTel Collector version 0.102.1 fixes this issue. It is also fixed in the confighttp module version 0.102.0 and configgrpc module version 0.102.1.

CVSS3: 8.2
1%
Низкий
больше 2 лет назад
nvd логотип
CVE-2024-36129

The OpenTelemetry Collector offers a vendor-agnostic implementation on how to receive, process and export telemetry data. An unsafe decompression vulnerability allows unauthenticated attackers to crash the collector via excessive memory consumption. OTel Collector version 0.102.1 fixes this issue. It is also fixed in the confighttp module version 0.102.0 and configgrpc module version 0.102.1.

CVSS3: 8.2
1%
Низкий
больше 2 лет назад
github логотип
GHSA-c74f-6mfw-mm4v

Denial of Service via Zip/Decompression Bomb sent over HTTP or gRPC

CVSS3: 8.2
1%
Низкий
больше 2 лет назад
fstec логотип
BDU:2024-05114

Уязвимость модулей confighttp и configgrpc программного обеспечения обработки данных телеметрии OpenTelemetry Collector, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 8.2
1%
Низкий
больше 2 лет назад

Уязвимостей на страницу

exploitDog - Комплексное решение для обнаружения, оценки и устранения уязвимостей.