Security Advisory

CVE-2024-36129

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2024-06-05 17:26:13
Last updated 2024-08-02 03:30:13
Assigner GitHub_M
State PUBLISHED

Description

The OpenTelemetry Collector offers a vendor-agnostic implementation on how to receive, process and export telemetry data. An unsafe decompression vulnerability allows unauthenticated attackers to crash the collector via excessive memory consumption. OTel Collector version 0.102.1 fixes this issue. It is also fixed in the confighttp module version 0.102.0 and configgrpc module version 0.102.1.