CVE-2026-54704
EUVD-2026-4115101.07.2026, 22:16
OpenTelemetry Java Instrumentation provides OpenTelemetry auto-instrumentation and instrumentation libraries for Java. In versions prior to 2.28.0, the JDBC auto-instrumentation may fail to sanitize passwords in SQL CONNECT statements when the password is double-quoted. As a result, clear-text database passwords can be added to trace span attributes and exported to observability backends. This issue has been fixed in version 2.28.0.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| linuxfoundation | opentelemetry_instrumentation_for_java | 𝑥 < 2.28.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration