Buffer overflow in OpenTelemetry Collector - CVE-2024-36129
Published: June 10, 2024
Vulnerability identifier: #VU91596
CSH Severity: High
CVSS v4: 8.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-36129
CWE-ID: CWE-119
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary error within the Zip/Decompression Bomb sent over HTTP or gRPC. A remote attacker can trigger memory corruption and cause a denial of service condition on the target system.
Affected software
OpenTelemetry Collector
Agent
Splunk Enterprise
Red Hat OpenShift distributed tracing (RHOSDT)
App Connect Enterprise Certified Container
Agent
Splunk Enterprise
Red Hat OpenShift distributed tracing (RHOSDT)
App Connect Enterprise Certified Container
How to mitigate CVE-2024-36129
Install updates from vendor's website.
OpenTelemetry Collector - addressed in versions 0.102.0, 0.102.1
Agent - update to 0.41.1
Splunk Enterprise - addressed in versions 9.1.7, 9.2.4, 9.3.2
Red Hat OpenShift distributed tracing (RHOSDT) - update to 3.2.1
App Connect Enterprise Certified Container - update to 5.0.19
Agent - update to 0.41.1
Splunk Enterprise - addressed in versions 9.1.7, 9.2.4, 9.3.2
Red Hat OpenShift distributed tracing (RHOSDT) - update to 3.2.1
App Connect Enterprise Certified Container - update to 5.0.19