漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
OpenTelemetry Rust: Unbounded memory allocation in W3C Baggage propagation
Vulnerability Description
OpenTelemetry Rust is the Rust OpenTelemetry implementation. In 0.32.0 and earlier, BaggagePropagator::extract_with_context in opentelemetry_sdk did not enforce W3C Baggage size limits before parsing an inbound baggage header, so a large attacker-controlled header could cause unnecessary CPU work and short-lived heap allocations while parsing entries later discarded by the SDK's baggage storage limits. Services that accept untrusted inbound propagation headers may experience increased per-request resource usage when processing oversized baggage headers. This issue is fixed in version 0.32.1.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Vulnerability Type
不加限制或调节的资源分配
Vulnerability Title
OpenTelemetry - CNCF OpenTelemetry Rust 资源管理错误漏洞
Vulnerability Description
OpenTelemetry - CNCF OpenTelemetry Rust是OpenTelemetry - CNCF组织的一个OpenTelemetry的Rust实现库。 OpenTelemetry - CNCF OpenTelemetry Rust 0.32.1之前版本存在资源管理错误漏洞,该漏洞源于在解析入站baggage标头前未强制执行W3C Baggage大小限制,可能导致大型攻击者控制的标头造成不必要的CPU工作和短时堆分配。
CVSS Information
N/A
Vulnerability Type
N/A