Beveiligingsadvies

CVE-2026-54704

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-07-01 21:15:37
Laatst bijgewerkt 2026-07-02 12:23:50
Toegewezen door GitHub_M
CVSS-score 6.5
Status PUBLISHED

Beschrijving

OpenTelemetry Java Instrumentation provides OpenTelemetry auto-instrumentation and instrumentation libraries for Java. In versions prior to 2.28.0, the JDBC auto-instrumentation may fail to sanitize passwords in SQL CONNECT statements when the password is double-quoted. As a result, clear-text database passwords can be added to trace span attributes and exported to observability backends. This issue has been fixed in version 2.28.0.