CVE-2024-38525
EUVD-2024-3739328.06.2024, 22:15
dd-trace-cpp is the Datadog distributed tracing for C++. When the library fails to extract trace context due to malformed unicode, it logs the list of audited headers and their values using the `nlohmann` JSON library. However, due to the way the JSON library is invoked, it throws an uncaught exception, which results in a crash. This vulnerability has been patched in version 0.2.2.Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| datadoghq | dd-trace-cpp | 𝑥 < 0.1.13 | ADP |
| datadoghq | dd-trace-cpp | 𝑥 < 0.2.2 | ADP |
Common Weakness Enumeration