opentelemetry-instrumentation Denial of Service vulnerability due to unbound cardinality metrics
CVE-2023-43810

7.5HIGH

Key Information:

Vendor
CVE Published:
6 October 2023

What is CVE-2023-43810?

OpenTelemetry, an open-source observability framework, is affected by a vulnerability that stems from unbound cardinality in the http_method label during autoinstrumentation. Attackers can exploit this flaw by sending numerous malicious requests with random and extended HTTP methods, potentially leading to memory exhaustion on the server. This issue arises when there is a lack of filtering for unknown HTTP methods at various layers, such as CDNs or load balancers. The vulnerability has been addressed in version 0.41b0.

Affected Version(s)

opentelemetry-python-contrib < 0.41b0

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.