The vendor explicitly identifies these products as affected by this CVE.
- opentelemetry-cpp.src as a component of Red Hat AMQ Clients
- firefox as a component of Red Hat Enterprise Linux 10
- firefox.src as a component of Red Hat Enterprise Linux 10
- thunderbird as a component of Red Hat Enterprise Linux 10
- thunderbird.src as a component of Red Hat Enterprise Linux 10
- firefox as a component of Red Hat Enterprise Linux 7
- firefox.src as a component of Red Hat Enterprise Linux 7
- firefox as a component of Red Hat Enterprise Linux 8
- firefox.src as a component of Red Hat Enterprise Linux 8
- thunderbird as a component of Red Hat Enterprise Linux 8
- thunderbird.src as a component of Red Hat Enterprise Linux 8
- firefox as a component of Red Hat Enterprise Linux 9
- Summary
- A flaw was found in opentelemetry-cpp. The OTLP HTTP exporters (traces/metrics/logs) read the full HTTP response into an in-memory vector of bytes without a size cap. This can be exploited by an attacker-controlled collector endpoint or a network attacker performing a Man-in-the-Middle (MITM) attack. Successful exploitation leads to memory exhaustion, resulting in a Denial of Service (DoS).
- Remediation
- Fix deferred
