以下是该漏洞描述的中文翻译: OpenTelemetry(又称 OTel)是一个厂商中立的开源可观测性框架,用于对遥测数据(如追踪、指标和日志)进行插桩、生成、收集和导出。 在 0.154.0 版本之前,Sentry 导出器通过 中的 和 函数,读取由远程 OTLP 发送端控制的 资源属性;随后在 中,将原始的项目 slug 传递给 和 ,并在运行时未通过 中的 应用 进行校验,直接将其插入到 Sentry API URL 中。 特殊字符可能导致预期的路径后缀在所有部署中变为查询参数,或在 Sentry 部署规范化
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| open-telemetry | github.com/open-telemetry/opentelemetry-collector-contrib/exporter/sentryexporter | < 0.154.0 |
affected |
| open-telemetry | opentelemetry-collector-contrib | < 0.154.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| open-telemetry | opentelemetry-collector-contrib | < 0.154.0 | - |
|
| open-telemetry | github.com/open-telemetry/opentelemetry-collector-contrib/exporter/sentryexporter | < 0.154.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet