OpenTelemetry-Go是OpenTelemetry - CNCF开源的一个开发者工具包。 OpenTelemetry-Go 1.36.0至1.40.0版本存在安全漏洞,该漏洞源于多值baggage标头提取独立解析每个标头字段值并跨值聚合成员,可能导致攻击者通过发送大量baggage标头行来放大CPU消耗和内存分配。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| open-telemetry | opentelemetry-go | >= 1.36.0, < 1.41.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| open-telemetry | opentelemetry-go | >= 1.36.0, < 1.41.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet