OpenTelemetry-Go is the Go implementation of OpenTelemetry. Prior to version 0.21.0, the exporters/otlp/otlplog/otlploggrpc package loads OTEL_EXPORTER_OTLP_LOGS_CERTIFICATE, OTEL_EXPORTER_OTLP_CERTIFICATE, and related client certificate environment variables through loadEnvTLS into cfg.tlsCfg, but newGRPCDialOptions does not apply cfg.tlsCfg when creating gRPC transport credentials. The environment-only TLS path instead uses credentials.NewTLS with system roots and no configured client certificate, bypassing intended private CA pinning and mutual TLS unless the application also supplies WithTLSCredentials. A network attacker able to intercept or spoof the collector connection with a system-trusted certificate can read or alter log telemetry. This issue is fixed in version 0.21.0.
The product does not validate, or incorrectly validates, a certificate.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Red Hat Hardened Images | RedHat | caddy-main-2.11.4-0.4.hum1 | * |
| Red Hat Hardened Images | RedHat | distribution-main-3.1.1-0.2.hum1 | * |
| Red Hat Hardened Images | RedHat | helm3-main-3.22.0-0.2.hum1 | * |
| Red Hat Hardened Images | RedHat | helm4-main-4.3.0-0.2.hum1 | * |
| Red Hat Hardened Images | RedHat | grafana12-4-main-12.4.10-0.5.hum1 | * |
| Red Hat Hardened Images | RedHat | grafana13-2-main-13.2.1-0.5.hum1 | * |
| Red Hat Hardened Images | RedHat | grafana12-4-main-12.4.10-0.6.hum1 | * |
| Red Hat Hardened Images | RedHat | tempo2-10-main-2.10.8-0.3.hum1 | * |
| Red Hat Hardened Images | RedHat | opentofu1-12-main-1.12.6-0.3.hum1 | * |
| Red Hat Hardened Images | RedHat | jaeger-main-2.20.0-0.9.hum1 | * |
| Red Hat Hardened Images | RedHat | tempo3-0-main-3.0.3-0.3.hum1 | * |
| Red Hat Hardened Images | RedHat | grafana13-1-main-13.1.6-0.2.hum1 | * |
| Red Hat Hardened Images | RedHat | loki3-6-main-3.6.17-0.2.hum1 | * |
| Red Hat Hardened Images | RedHat | loki3-7-main-3.7.8-0.2.hum1 | * |