Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2024-42368

20
FAUCET Score

CVE-2024-42368 affects OpenTelemetry (OTel) collectors utilizing the bearertokenauth extension, where a timing attack vulnerability exists due to a non-constant time string comparison for bearer tokens. This allows malicious clients with network access to guess the configured token, potentially enabling the introduction of fabricated or bad data into the telemetry pipeline. The vulnerability has a CVSS score of 6.5 (Medium), indicating network-based exploitation with low attack complexity, leading to potential low integrity and availability impacts. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
Open-TelemetryOpentelemetry-Collector-Contrib
>= 0.80.0, < 0.107.0CNA affected

CVSS Data

CVSS version used by this source: 3.1

6.5MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
LOW
Availability Impact
LOW
Exploitability Score
3.9
Impact Score
2.5
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.62%
Probability of exploitation in next 30 days
EPSS Percentile
46.1%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0062 is in the 29th percentile among its peer group of 23,725 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (3)

gopatch availablevia ghsa
Product: github.com/open-telemetry/opentelemetry-collector-contrib/extension/bearertokenauthextensionFixed in: 0.107.0
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: opentelemetry-collector
redhatno patchvia redhat_api
Product: Red Hat OpenShift distributed tracing 3Fixed in: rhosdt/opentelemetry-collector-rhel8

Vendor Advisories (2)

goGHSA-rfxf-mf63-cpqvmedium

open-telemetry has an Observable Timing Discrepancy

Aug 13, 2024
redhatCVE-2024-42368Moderate

bearertokenauthextension: Observable Timing Discrepancy in github.com/open-telemetry/opentelemetry-collector-contrib/extension/bearertokenauthextension

Aug 13, 2024

References

github.com / open-telemetry/opentelemetry-collector-contrib/commit/c9bd3eff0bb357d9c812a0d8defd3b09db95699a
github.com / open-telemetry/opentelemetry-collector-contrib/pull/34516
github.com / open-telemetry/opentelemetry-collector-contrib/security/advisories/GHSA-rfxf-mf63-cpqv