漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
OpenTelemetry Javaagent RMI context propagation allows resource exhaustion
Vulnerability Description
OpenTelemetry Java Instrumentation provides OpenTelemetry auto-instrumentation and instrumentation libraries for Java. In versions prior to 2.27.0, the RMI context propagation payload reader limits the number of context entries but does not limit the aggregate size of the strings read from the stream. An attacker who can reach an RMI endpoint on an instrumented JVM can send an oversized context propagation payload. This can cause excessive memory allocation while the JVM reads the payload, potentially leading to denial of service. The issue affects only deployments where RMI instrumentation is enabled and an RMI endpoint is network-reachable. This issue has been fixed in version 2.27.0.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Vulnerability Type
未加控制的资源消耗(资源穷尽)
Vulnerability Title
open-telemetry opentelemetry-java-instrumentation 资源管理错误漏洞
Vulnerability Description
open-telemetry opentelemetry-java-instrumentation是open-telemetry组织的一款Java应用的观测性数据采集组件。 open-telemetry opentelemetry-java-instrumentation 2.27.0之前版本存在资源管理错误漏洞,该漏洞源于RMI上下文传播有效载荷读取器未限制从流中读取字符串的聚合大小,可能导致攻击者发送过大有效载荷,造成过度内存分配,从而引发拒绝服务。
CVSS Information
N/A
Vulnerability Type
N/A