以下是对该漏洞描述的中文翻译: dd-trace-rs 为 Rust 应用提供 Datadog 应用程序性能监控。在版本 0.1.0 至 0.3.3 中, 在解析 W3C 请求头时,会将 Datadog 供应商条目中所有以分号分隔的键值对收集到 中,但并未对键值对的数量或条目大小设置限制。由于 tracecontext 提取功能默认开启,远程未认证的攻击者可以发送一个任意大的 条目,从而在每个请求中导致过高的 CPU 和内存消耗,进而造成受监控网络服务的拒绝服务(DoS)。该漏洞已在版本 0.3.3 中修复。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| DataDog | dd-trace-rs | >= 0.1.0, < 0.3.3 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| DataDog | dd-trace-rs | >= 0.1.0, < 0.3.3 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet