CVE-2024-42368 affects OpenTelemetry (OTel) collectors utilizing the bearertokenauth extension, where a timing attack vulnerability exists due to a non-constant time string comparison for bearer tokens. This allows malicious clients with network access to guess the configured token, potentially enabling the introduction of fabricated or bad data into the telemetry pipeline. The vulnerability has a CVSS score of 6.5 (Medium), indicating network-based exploitation with low attack complexity, leading to potential low integrity and availability impacts. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Open-Telemetry | Opentelemetry-Collector-Contrib | >= 0.80.0, < 0.107.0CNA affected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.