Impact
The OpenTelemetry-Go log gRPC exporter unintentionally ignores TLS certificates set via environment variables, causing the exporter to use system root CAs without a client certificate when establishing gRPC connections. This flaw bypasses intended private CA pinning and mutual TLS, lowering the confidentiality and integrity protection of log telemetry. Attackers who can intercept or spoof the collector connection with a system‑trusted certificate could read or alter log data, which aligns with CWE‑295 (Improper Certificate Validation) and CWE‑923 (Inner‑TLS‑Related Misconfiguration).
Affected Systems
All releases of OpenTelemetry-Go prior to 0.21.0 that use the exporters/otlp/otlplog/otlploggrpc package are affected. The issue applies to the OpenTelemetry-Go project maintained by the OpenTelemetry community, specifically any Go applications that import and use the OTLP gRPC log exporter without providing explicit TLS credentials.
Risk and Exploitability
The vulnerability carries a CVSS score of 6.3, indicating moderate severity, while the EPSS score of less than 1% shows a low likelihood of exploitation in the current environment. The vulnerability is not listed in CISA’s KEV catalog. An attacker would need network access to the telemetry channel and the ability to present a system‑trusted certificate to impersonate the collector. The primary risk is compromise of log confidentiality and integrity rather than availability.
OpenCVE Enrichment
Github GHSA