dd-trace-rs: Unbounded W3C tracestate parsing may lead to DoS
21Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 7.5epss 0.6%
probabilidad de explotación
0.6%top 54% de las CVE
explotación observada
noninguna fuente lo reporta
dd-trace-rs provides Datadog application performance monitoring for Rust. From 0.1.0 until 0.3.3, datadog-opentelemetry/src/propagation/tracecontext.rs parses the W3C tracestate header and collects every semicolon-separated key and value pair in the Datadog dd=... vendor entry into a HashMap without enforcing a pair count or entry size limit. Because tracecontext extraction is enabled by default, a remote unauthenticated attacker can send an arbitrarily large dd=... entry and force excessive CPU and memory consumption for each request, causing denial of service in an instrumented network service. This vulnerability is fixed in 0.3.3.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Productos afectados
DataDog · dd-trace-rsReferencias
https://github.com/DataDog/dd-trace-rs/commit/77c5d185c71d0ea8103da0e6cf4cd50677ffacd2https://github.com/DataDog/dd-trace-rs/pull/218https://github.com/DataDog/dd-trace-rs/releases/tag/datadog-opentelemetry-v0.3.3https://github.com/DataDog/dd-trace-rs/security/advisories/GHSA-gpwf-4h98-v82q