Remote Code Execution (RCE) vulnerability
Introduced through
OpenTelemetry.Exporter.Console@1.3.0
Fixed in
System.Text.Encodings.Web@4.5.1, @4.7.2, @5.0.1
Exploit maturity
NO KNOWN EXPLOIT
Show less detail
Detailed paths
Introduced through: Centene.Observability@* › OpenTelemetry.Exporter.Console@1.3.0 › System.Text.Json@4.7.0 › System.Text.Encodings.Web@4.7.0
Fix: No remediation path available.
Same happens in the latest version - 1.4.0-beta.1. We need to switch to System.Text.Json version 4.7.2.
Remote Code Execution (RCE) vulnerability
Introduced through
OpenTelemetry.Exporter.Console@1.3.0
Fixed in
System.Text.Encodings.Web@4.5.1, @4.7.2, @5.0.1
Exploit maturity
NO KNOWN EXPLOIT
Show less detail
Detailed paths
Introduced through: Centene.Observability@* › OpenTelemetry.Exporter.Console@1.3.0 › System.Text.Json@4.7.0 › System.Text.Encodings.Web@4.7.0
Fix: No remediation path available.
Same happens in the latest version - 1.4.0-beta.1. We need to switch to System.Text.Json version 4.7.2.