The OpenTelemetry Collector offers a vendor-agnostic implementation on how to receive, process and export telemetry data. An unsafe decompression vulnerability allows unauthenticated attackers to crash the collector via excessive memory consumption. OTel Collector version 0.102.1 fixes this issue. It is also fixed in the confighttp module version 0.102.0 and configgrpc module version 0.102.1.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: GitHub_M
Published: 2024-06-05T17:26:13.903Z
Updated: 2024-08-02T03:30:13.165Z
Reserved: 2024-05-20T21:07:48.190Z
Link: CVE-2024-36129
Vulnrichment
Updated: 2024-07-19T12:59:27.966Z
NVD
Status : Modified
Published: 2024-06-05T18:15:10.833
Modified: 2024-11-21T09:21:40.733
Link: CVE-2024-36129
Redhat