GHSA-f8pq-3926-8gx5

    Dashboard / Vulnerabilities / GHSA-f8pq-3926-8gx5

    GHSA-f8pq-3926-8gx5

    Published: 9 Aug 2023Last Modified: 9 Aug 2023

    Summary: Unsanitized user controlled input in module generation

    Details: ## Impact The `import-in-the-middle` loader used by `@opentelemetry/instrumentation` works by generating a wrapper module on the fly. The wrapper uses the module specifier to load the original module and add some wrapping code. It allows for remote code execution in cases where an application passes user-supplied input directly to an `import()` function. ## Patches This vulnerability has been patched in `@opentelemetry/instrumentation` version `0.41.2` ## Workarounds - Do not pass any user-supplied input to `import()`. Instead, verify it against a set of allowed values. - If using `@opentelemetry/instrumentation` with support for EcmaScript Modules is not needed, ensure that none of the following options are set (either via command-line or the `NODE_OPTIONS` environment variable): ``` --experimental-loader=@opentelemetry/instrumentation/hook.mjs --experimental-loader @opentelemetry/instrumentation/hook.mjs --loader=import-in-the-middle/hook.mjs --loader import-in-the-middle/hook.mjs ``` ## References - https://github.com/DataDog/import-in-the-middle/security/advisories/GHSA-5r27-rw8r-7967

    Affected packages

    Package

    Name: @opentelemetry/instrumentation

    Purl: pkg:npm/%40opentelemetry/instrumentation

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 0.40.0
    Fixed -0.41.2

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-f8pq-3926-8gx5 | CVE-DB