OpenTelemetry-Go
cpe:2.3:a:linuxfoundation:opentelemetry-go:*:*:*:*:go:*:*
- >= 1.21.0, <= 1.39.0
A path hijacking vulnerability allowing arbitrary code execution has been identified in the OpenTelemetry Go SDK, specifically in versions 1.20.0 prior to 1.39.0. This issue arises on macOS systems, where the resource detection code executes the 'ioreg' command using a search path. An attacker who can locally modify the PATH environment variable could exploit this vulnerability to execute arbitrary code within the application's context.
Exploitation of this vulnerability could lead to arbitrary code execution within the context of the application.
Users can upgrade to OpenTelemetry Go SDK version 1.40.0 or later to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.