Information Exposure Affecting github.com/open-telemetry/opentelemetry-collector-contrib/receiver/awsfirehosereceiver package, versions >=0.49.0 <0.108.0
Threat Intelligence
EPSS
0.04% (15th
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-GOLANG-GITHUBCOMOPENTELEMETRYOPENTELEMETRYCOLLECTORCONTRIBRECEIVERAWSFIREHOSERECEIVER-7850193
- published 29 Aug 2024
- disclosed 28 Aug 2024
- credit Douglas Heriot
Introduced: 28 Aug 2024
CVE-2024-45043 Open this link in a new tabHow to fix?
Upgrade github.com/open-telemetry/opentelemetry-collector-contrib/receiver/awsfirehosereceiver
to version 0.108.0 or higher.
Overview
Affected versions of this package are vulnerable to Information Exposure through the awsfirehosereceiver
module which accepts incoming requests with no key.