CVE-2023-43810
Last modified
CVE-2023-43810 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. OpenTelemetry, also known as OTel for short, is a vendor-neutral open-source Observability framework for instrumenting, generating, collecting, and exporting telemetry data such as traces, metrics, logs. Autoinstrumentation out of the box adds the label `http_method` that has unbound cardinality. EPSS estimates a 0.69% chance of exploitation in the next 30 days.
Description
OpenTelemetry, also known as OTel for short, is a vendor-neutral open-source Observability framework for instrumenting, generating, collecting, and exporting telemetry data such as traces, metrics, logs. Autoinstrumentation out of the box adds the label `http_method` that has unbound cardinality. It leads to the server's potential memory exhaustion when many malicious requests are sent. HTTP method for requests can be easily set by an attacker to be random and long. In order to be affected program has to be instrumented for HTTP handlers and does not filter any unknown HTTP methods on the level of CDN, LB, previous middleware, etc. This issue has been patched in version 0.41b0.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Opentelemetry | Opentelemetry | < 0.41b0 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-43810?
How severe is CVE-2023-43810?
How do I fix CVE-2023-43810?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-43802Arduino Create Agent is a package to help manage Arduino dev…7.8
- CVE-2023-43803Arduino Create Agent is a package to help manage Arduino dev…7.1
- CVE-2023-43804urllib3 is a user-friendly HTTP client library for Python. u…8.1
- CVE-2023-43805Nexkey is a fork of Misskey, an open source, decentralized s…7.5
- CVE-2023-43809Soft Serve is a self-hostable Git server for the command lin…7.5
- CVE-2023-4381Unverified Password Change in GitHub repository instantsoft/…4.3
- CVE-2023-43813GLPI is a free asset and IT management software package. Sta…8.8
- CVE-2023-43814Discourse is an open source platform for community discussio…3.7
- CVE-2023-43815A buffer overflow vulnerability exists in Delta Electronics …7.8
- CVE-2023-43816A buffer overflow vulnerability exists in Delta Electronics …7.8
- CVE-2023-43817A buffer overflow exists in Delta Electronics Delta Industri…7.8
- CVE-2023-43818A buffer overflow exists in Delta Electronics Delta Industri…7.8
Are you affected by CVE-2023-43810?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
