1
+ {
2
+ "schema_version" : " 1.3.1" ,
3
+ "id" : " GO-2023-2113" ,
4
+ "modified" : " 0001-01-01T00:00:00Z" ,
5
+ "published" : " 0001-01-01T00:00:00Z" ,
6
+ "aliases" : [
7
+ " CVE-2023-45142" ,
8
+ " GHSA-rcjv-mgp8-qvmr"
9
+ ],
10
+ "summary" : " Memory exhaustion in github.com/open-telemetry/opentelemetry-go-contrib" ,
11
+ "details" : " Memory exhaustion in github.com/open-telemetry/opentelemetry-go-contrib" ,
12
+ "affected" : [
13
+ {
14
+ "package" : {
15
+ "name" : " go.opentelemetry.io/contrib/instrumentation/github.com/emicklei/go-restful/otelrestful" ,
16
+ "ecosystem" : " Go"
17
+ },
18
+ "ranges" : [
19
+ {
20
+ "type" : " SEMVER" ,
21
+ "events" : [
22
+ {
23
+ "introduced" : " 0"
24
+ },
25
+ {
26
+ "fixed" : " 0.44.0"
27
+ }
28
+ ]
29
+ }
30
+ ],
31
+ "ecosystem_specific" : {
32
+ "imports" : [
33
+ {
34
+ "path" : " go.opentelemetry.io/contrib/instrumentation/github.com/emicklei/go-restful/otelrestful/internal/semconvutil" ,
35
+ "symbols" : [
36
+ " HTTPClientRequest" ,
37
+ " HTTPServerRequest" ,
38
+ " httpConv.ClientRequest" ,
39
+ " httpConv.ServerRequest" ,
40
+ " httpConv.proto"
41
+ ]
42
+ }
43
+ ]
44
+ }
45
+ },
46
+ {
47
+ "package" : {
48
+ "name" : " go.opentelemetry.io/contrib/instrumentation/github.com/gin-gonic/gin/otelgin" ,
49
+ "ecosystem" : " Go"
50
+ },
51
+ "ranges" : [
52
+ {
53
+ "type" : " SEMVER" ,
54
+ "events" : [
55
+ {
56
+ "introduced" : " 0"
57
+ },
58
+ {
59
+ "fixed" : " 0.44.0"
60
+ }
61
+ ]
62
+ }
63
+ ],
64
+ "ecosystem_specific" : {
65
+ "imports" : [
66
+ {
67
+ "path" : " go.opentelemetry.io/contrib/instrumentation/github.com/gin-gonic/gin/otelgin/internal/semconvutil" ,
68
+ "symbols" : [
69
+ " HTTPClientRequest" ,
70
+ " HTTPServerRequest" ,
71
+ " httpConv.ClientRequest" ,
72
+ " httpConv.ServerRequest" ,
73
+ " httpConv.proto"
74
+ ]
75
+ }
76
+ ]
77
+ }
78
+ },
79
+ {
80
+ "package" : {
81
+ "name" : " go.opentelemetry.io/contrib/instrumentation/github.com/gorilla/mux/otelmux" ,
82
+ "ecosystem" : " Go"
83
+ },
84
+ "ranges" : [
85
+ {
86
+ "type" : " SEMVER" ,
87
+ "events" : [
88
+ {
89
+ "introduced" : " 0"
90
+ },
91
+ {
92
+ "fixed" : " 0.44.0"
93
+ }
94
+ ]
95
+ }
96
+ ],
97
+ "ecosystem_specific" : {
98
+ "imports" : [
99
+ {
100
+ "path" : " go.opentelemetry.io/contrib/instrumentation/github.com/gorilla/mux/otelmux/internal/semconvutil" ,
101
+ "symbols" : [
102
+ " HTTPClientRequest" ,
103
+ " HTTPServerRequest" ,
104
+ " httpConv.ClientRequest" ,
105
+ " httpConv.ServerRequest" ,
106
+ " httpConv.proto"
107
+ ]
108
+ }
109
+ ]
110
+ }
111
+ },
112
+ {
113
+ "package" : {
114
+ "name" : " go.opentelemetry.io/contrib/instrumentation/github.com/labstack/echo/otelecho" ,
115
+ "ecosystem" : " Go"
116
+ },
117
+ "ranges" : [
118
+ {
119
+ "type" : " SEMVER" ,
120
+ "events" : [
121
+ {
122
+ "introduced" : " 0"
123
+ },
124
+ {
125
+ "fixed" : " 0.44.0"
126
+ }
127
+ ]
128
+ }
129
+ ],
130
+ "ecosystem_specific" : {
131
+ "imports" : [
132
+ {
133
+ "path" : " go.opentelemetry.io/contrib/instrumentation/github.com/labstack/echo/otelecho/internal/semconvutil" ,
134
+ "symbols" : [
135
+ " HTTPClientRequest" ,
136
+ " HTTPServerRequest" ,
137
+ " httpConv.ClientRequest" ,
138
+ " httpConv.ServerRequest" ,
139
+ " httpConv.proto"
140
+ ]
141
+ }
142
+ ]
143
+ }
144
+ },
145
+ {
146
+ "package" : {
147
+ "name" : " go.opentelemetry.io/contrib/instrumentation/gopkg.in/macaron.v1/otelmacaron" ,
148
+ "ecosystem" : " Go"
149
+ },
150
+ "ranges" : [
151
+ {
152
+ "type" : " SEMVER" ,
153
+ "events" : [
154
+ {
155
+ "introduced" : " 0"
156
+ },
157
+ {
158
+ "fixed" : " 0.44.0"
159
+ }
160
+ ]
161
+ }
162
+ ],
163
+ "ecosystem_specific" : {
164
+ "imports" : [
165
+ {
166
+ "path" : " go.opentelemetry.io/contrib/instrumentation/gopkg.in/macaron.v1/otelmacaron/internal/semconvutil" ,
167
+ "symbols" : [
168
+ " HTTPClientRequest" ,
169
+ " HTTPServerRequest" ,
170
+ " httpConv.ClientRequest" ,
171
+ " httpConv.ServerRequest" ,
172
+ " httpConv.proto"
173
+ ]
174
+ }
175
+ ]
176
+ }
177
+ },
178
+ {
179
+ "package" : {
180
+ "name" : " go.opentelemetry.io/contrib/instrumentation/net/http/httptrace/otelhttptrace" ,
181
+ "ecosystem" : " Go"
182
+ },
183
+ "ranges" : [
184
+ {
185
+ "type" : " SEMVER" ,
186
+ "events" : [
187
+ {
188
+ "introduced" : " 0"
189
+ },
190
+ {
191
+ "fixed" : " 0.44.0"
192
+ }
193
+ ]
194
+ }
195
+ ],
196
+ "ecosystem_specific" : {
197
+ "imports" : [
198
+ {
199
+ "path" : " go.opentelemetry.io/contrib/instrumentation/net/http/httptrace/otelhttptrace/internal/semconvutil" ,
200
+ "symbols" : [
201
+ " HTTPClientRequest" ,
202
+ " HTTPServerRequest" ,
203
+ " httpConv.ClientRequest" ,
204
+ " httpConv.ServerRequest" ,
205
+ " httpConv.proto"
206
+ ]
207
+ }
208
+ ]
209
+ }
210
+ },
211
+ {
212
+ "package" : {
213
+ "name" : " go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp" ,
214
+ "ecosystem" : " Go"
215
+ },
216
+ "ranges" : [
217
+ {
218
+ "type" : " SEMVER" ,
219
+ "events" : [
220
+ {
221
+ "introduced" : " 0"
222
+ },
223
+ {
224
+ "fixed" : " 0.44.0"
225
+ }
226
+ ]
227
+ }
228
+ ],
229
+ "ecosystem_specific" : {
230
+ "imports" : [
231
+ {
232
+ "path" : " go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp" ,
233
+ "symbols" : [
234
+ " middleware.serveHTTP"
235
+ ]
236
+ }
237
+ ]
238
+ }
239
+ }
240
+ ],
241
+ "references" : [
242
+ {
243
+ "type" : " ADVISORY" ,
244
+ "url" : " https://github.com/open-telemetry/opentelemetry-go-contrib/security/advisories/GHSA-rcjv-mgp8-qvmr"
245
+ },
246
+ {
247
+ "type" : " FIX" ,
248
+ "url" : " https://github.com/open-telemetry/opentelemetry-go-contrib/pull/4277"
249
+ }
250
+ ],
251
+ "database_specific" : {
252
+ "url" : " https://pkg.go.dev/vuln/GO-2023-2113"
253
+ }
254
+ }
0 commit comments