CVE-2023-47108

OpenTelemetry-Go Contrib is a collection of third-party packages for OpenTelemetry-Go. Starting in version 0.37.0 and prior to version 0.46.0, the grpc Unary Server Interceptor out of the box adds labels `net.peer.sock.addr` and `net.peer.sock.port` that have unbound cardinality. It leads to the server's potential memory exhaustion when many malicious requests are sent. An attacker can easily flood the peer address and port for requests. Version 0.46.0 contains a fix for this issue. As a workaround to stop being affected, a view removing the attributes can be used. The other possibility is to disable grpc metrics instrumentation by passing `otelgrpc.WithMeterProvider` option with `noop.NewMeterProvider`.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 72%
Affected Products (NVD)
VendorProductVersion
opentelemetryopentelemetry
𝑥
< 0.46.0
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
golang-opentelemetry-contrib
focal
dne
jammy
dne
mantic
dne
noble
dne
oracular
needs-triage
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
containerd
suse enterprise desktop 15 SP7
1.7.21-150000.117.1
fixed
suse enterprise sap 15 SP5
1.7.21-150000.117.1
fixed
suse enterprise sap 15 SP6
1.7.21-150000.117.1
fixed
suse enterprise sap 15 SP7
1.7.21-150000.117.1
fixed
suse enterprise server 15 SP2
1.7.21-150000.117.1
fixed
suse enterprise server 15 SP3
1.7.21-150000.117.1
fixed
suse enterprise server 15 SP4
1.7.21-150000.117.1
fixed
suse enterprise server 15 SP5
1.7.21-150000.117.1
fixed
suse enterprise server 15 SP6
1.7.21-150000.117.1
fixed
suse enterprise server 15 SP7
1.7.21-150000.117.1
fixed
containerd-ctr
suse enterprise sap 15 SP5
1.7.21-150000.117.1
fixed
suse enterprise sap 15 SP6
1.7.21-150000.117.1
fixed
suse enterprise sap 15 SP7
1.7.21-150000.117.1
fixed
suse enterprise server 15 SP2
1.7.21-150000.117.1
fixed
suse enterprise server 15 SP3
1.7.21-150000.117.1
fixed
suse enterprise server 15 SP4
1.7.21-150000.117.1
fixed
suse enterprise server 15 SP5
1.7.21-150000.117.1
fixed
suse enterprise server 15 SP6
1.7.21-150000.117.1
fixed
suse enterprise server 15 SP7
1.7.21-150000.117.1
fixed
containerd-devel
suse enterprise sap 15 SP5
1.7.21-150000.117.1
fixed
suse enterprise sap 15 SP6
1.7.21-150000.117.1
fixed
suse enterprise sap 15 SP7
1.7.21-150000.117.1
fixed
suse enterprise server 15 SP4
1.7.21-150000.117.1
fixed
suse enterprise server 15 SP5
1.7.21-150000.117.1
fixed
suse enterprise server 15 SP6
1.7.21-150000.117.1
fixed
suse enterprise server 15 SP7
1.7.21-150000.117.1
fixed
Amazon Linux logo
Amazon Linux Releases
Amazon Package
Release
amazon-cloudwatch-agent
Amazon Linux 2
0:1.300032.3-1.amzn2
fixed
Amazon Linux 2023
0:1.300032.3-1.amzn2023
fixed
Azure Linux logo
Azure Linux Releases
Azure Package
Release
containerd
Azure Linux 3.0
0:1.7.13-3.azl3
fixed
docker-buildx
Azure Linux 3.0
0:0.14.0-1.azl3
fixed
docker-compose
Azure Linux 3.0
0:2.27.0-1.azl3
fixed
ig
Azure Linux 3.0
0:0.30.0-1.azl3
fixed
kube-vip-cloud-provider
Azure Linux 3.0
0:0.0.10-1.azl3
fixed
moby-containerd-cc
Azure Linux 3.0
0:1.7.7-3.azl3
fixed
CBL-Mariner 2.0
0:1.7.2-3.cm2
fixed
References