PT-2026-54844 · Unknown · @Opentelemetry/Instrumentation
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
OpenTelemetry Java Instrumentation versions prior to 2.28.0
Description
The JDBC auto-instrumentation fails to sanitize passwords in SQL CONNECT statements when the password is enclosed in double quotes. This leads to clear-text database passwords being included in trace span attributes and subsequently exported to observability backends.
Recommendations
Update to version 2.28.0.
Exploit
Fix
Insertion into Log File
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
@Opentelemetry/Instrumentation