Résumé
OpenTelemetry Java Instrumentation: JDBC Auto-Instrumentation Logging Clear-Text Passwords
Détails de l’avis
OpenTelemetry Java Instrumentation JDBC auto-instrumentation may fail to sanitize passwords in SQL CONNECT statements when the password is double-quoted. As a result, clear-text database passwords can be added to trace span attributes and exported to observability backends.
Références
- https://github.com/advisories/GHSA-rwqx-fvqh-6wm4
- https://github.com/open-telemetry/opentelemetry-java-instrumentation/security/advisories/GHSA-rwqx-fvqh-6wm4
- https://nvd.nist.gov/vuln/detail/CVE-2026-54704
- https://github.com/open-telemetry/opentelemetry-java-instrumentation/pull/18754
- https://github.com/open-telemetry/opentelemetry-java-instrumentation/commit/7ac7fa6fda6c2e3b65bc5d3c6eba050311a49511
- https://github.com/open-telemetry/opentelemetry-java-instrumentation/releases/tag/v2.28.0
Vulnérabilités liées
Tout Supply chain →- HIGHCVE-2026-61798
netty-incubator-codec-ohttp: BoringSSL HPKE private key bytes exposed through toString() and exception messages
- MEDIUMGHSA-hjwh-xvfw-qrwj
SearXNG Basic Authentication Credentials Exposed Through MCP Logs and JSON-RPC Error Responses
- HIGHGHSA-p77j-g7h5-r2vw
GeoLens's authorization and cache-scope flaws disclose private dataset data and metadata to unauthorized users (fixed in 1.2.4)
- MEDIUMCVE-2026-55102
hashi-vault-js: Vault token and secret values exposed in thrown errors
- MEDIUMCVE-2026-65589
n8n: Custom Header Credential Values Leaked in Plaintext into LLM Node Execution Data
- MEDIUMGHSA-fmvg-vhqq-r2mj
Duplicate Advisory: Custom Header Credential Values Leaked in Plaintext into LLM Node Execution Data