NA

CVE-2023-47108

Published: 10/11/2023 Updated: 20/11/2023
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

Description<!---->A memory exhaustion flaw was found in the otelgrpc handler of open-telemetry. This flaw may allow a remote unauthenticated malicious user to flood the peer address and port and exhaust the server's memory by sending multiple malicious requests, affecting the availability of the system.A memory exhaustion flaw was found in the otelgrpc handler of open-telemetry. This flaw may allow a remote unauthenticated malicious user to flood the peer address and port and exhaust the server's memory by sending multiple malicious requests, affecting the availability of the system.

Vulnerable Product Search on Vulmon Subscribe to Product

opentelemetry opentelemetry

Vendor Advisories

Synopsis Critical: OpenShift Container Platform 41411 bug fix and security update Type/Severity Security Advisory: Critical Topic An update is now available for Red Hat OpenShift Container Platform 414Red Hat Product Security has rated this update as having a security impact of Critical A Common Vulnerability Scoring System (CVSS) base s ...
Synopsis Important: OpenShift Container Platform 4147 bug fix and security update Type/Severity Security Advisory: Important Topic Red Hat OpenShift Container Platform release 4147 is now available with updates to packages and images that fix several bugs and add enhancementsThis release includes a security update for Red Hat OpenShift C ...
Synopsis Important: OpenShift Container Platform 4146 security and extras update Type/Severity Security Advisory: Important Topic Red Hat OpenShift Container Platform release 4146 is now available with updates to packages and images that fix several bugsThis release includes a security update for Red Hat OpenShift Container Platform 414 ...
Synopsis Moderate: OpenShift Container Platform 41330 security update Type/Severity Security Advisory: Moderate Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic Red Hat OpenShift Container Platform release 41330 is now available with updates to packages and ima ...
Synopsis Moderate: OpenShift Container Platform 4149 packages and security update Type/Severity Security Advisory: Moderate Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic Red Hat OpenShift Container Platform release 4149 is now available with updates to packa ...
Synopsis Moderate: OpenShift Container Platform 4149 bug fix and security update Type/Severity Security Advisory: Moderate Topic Red Hat OpenShift Container Platform release 4149 is now available with updates to packages and images that fix several bugs and add enhancementsThis release includes a security update for Red Hat OpenShift Con ...
Synopsis Moderate: OpenShift Container Platform 41248 packages and security update Type/Severity Security Advisory: Moderate Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic Red Hat OpenShift Container Platform release 41248 is now available with updates to pac ...
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023 (CVE-2023-39325) A malicious HTTP sender can use chunk extensions to cause a receiver reading from a request or response body to read many more bytes from ...
Description<!---->A memory exhaustion flaw was found in the otelgrpc handler of open-telemetry This flaw may allow a remote unauthenticated attacker to flood the peer address and port and exhaust the server's memory by sending multiple malicious requests, affecting the availability of the systemA memory exhaustion flaw was found in the otelgrpc h ...