[SECURITY] Transitive Vulnerabilities In CivetWeb via Prometheus-Cpp
Los mantenedores suelen responder en 1 día
Nadie ha tomado este issue todavía.
Evaluación
- Dificultad
- 5/5
- Tiempo estimado
- Más de una semana
- Aptitud para principiantes
- 30/100
- Tipo de issue
- Error
- Claridad
- Necesita aclaración
- Estado de actividad
- Activo
- Área
- observability, security
Línea de trabajo
Comienza revisando la ruta de dependencias del exportador de Prometheus a través de prometheus-cpp hasta CivetWeb, junto con las vulnerabilidades de Lua y cJSON enumeradas y el issue enlazado de prometheus-cpp. No se mencionan archivos fuente ni pruebas. Para darlo por terminado sería necesaria una decisión de un maintainer y un alcance acordado para actualizar las dependencias o reemplazar la dependencia afectada del exportador.
Escrito por el modelo de indexación a partir del texto del issue.
Descripción
Writing this as a normal bug rather than a vulnerability report because this is a report of issues with a dependency, not a new report of a vulnerability in OpenTelemetry itself.
Background Context
Opening this issue because I began consuming OpenTelemetry for a project, and I'm starting to run into issues flagged by my dependency scanning tools with CivetWeb, consumed by this project by way of prometheus-cpp. I have logged an issue with this repo's maintainers as well, saying more or less the same things I am saying here, with a desire to build awareness as much as I can.
Matching issue in prometheus-cpp
Impact
At this stage, because of these unfixed CVEs, the only way I can use OpenTelemetry in my project is by ensuring I do not build or use the Prometheus exporter whatsoever. If I happened to need to use Prometheus as my exporter, I would not be able to use OpenTelemetry.
Details
Several of the vulnerabilities I've mentioned were already logged in CivetWeb but I've logged a couple myself to make the maintainers aware.
Specifically the issues that have been flagged thus far are:
CVE-2021-44964: Resolvable by updating Lua to v5.4.4+
CVE-2022-28805: Resolvable by updating Lua to v5.4.4+
CVE-2025-55763: Fix seems to exist based on issue discussion but is as yet unreleased
CVE-2026-5789: As yet unfixed in CivetWeb
CVE-2025-57052: Resolvable by updating cJSON to v1.7.19+ (not an issue with live code -- civetweb uses cJSON in example usage code only as far as I can tell, but it does still trip automated security scans. Including for completeness)
Normally, I'd just write this up for CivetWeb, but unfortunately earlier this year the primary maintainer of that library has made statements that suggest we should not expect fixes on any consistent timeframe. Maintainer’s commentary. Looking at my calendar, I don't expect I will have bandwidth to address the dependency updates myself either.
Writing to ask if the maintainers of this repo were aware of these security issues and whether any thought was given to finding a replacement for CivetWeb and/or reconsidering usage of Prometheus in this project.
- Lenguaje dominante
- C++
- Estrellas
- 1.4k
- Forks
- 640
- Merge medio
- 1 d 2 h
- PR fusionados (30 d)
- 73
Preparar el entorno
Inicia el contenedor de desarrollo del proyecto en tu navegador, con tu propia cuenta de GitHub.
- Sin Dockerfile ni archivo de Docker Compose
- Tiene una plantilla de pull request
- Leer la guía de contribución
Primeros pasos
- Lee el issue completo y luego la guía de contribución del proyecto.
- Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
- Haz un fork del repositorio y trabaja en una rama.
- Abre un pull request que haga referencia al número del issue.
Más de open-telemetry/opentelemetry-cpp
-
[CI] Add Ubuntu 26.04 runners to the CI workflowPosiblemente ocupada @deodattap la tomó hace 7 días. Abiertotriage/accepted
Dificultad 2/5 1-3 horas Aptitud para principiantes 72/100
open-telemetry/opentelemetry-cpp#4596 · 2 comentarios · 1 reacción ·
Los mantenedores suelen responder en 1 día
-
[BUG] Resource::Create() throws bad_variant_access if process.executable.name isn't a stringPosiblemente ocupada @ryux1 la tomó hace 29 días. Abiertobug help wanted triage/accepted
Dificultad 2/5 1-3 horas Aptitud para principiantes 84/100
open-telemetry/opentelemetry-cpp#4535 · 1 comentario · 2 reacciones ·
Los mantenedores suelen responder en 1 día
-
[BUG] OnResponse() can call std::terminate() when the response body fails to parse as JSON/protobufPosiblemente ocupada @YuEfSaEDU la tomó hace 20 días. Abiertobug help wanted triage/accepted
Dificultad 2/5 1-3 horas Aptitud para principiantes 78/100
open-telemetry/opentelemetry-cpp#4534 · 2 comentarios · 1 reacción ·
Los mantenedores suelen responder en 1 día
-
[BUG] ETW Properties::to_vector doubles the result and reads past a string_viewPosiblemente ocupada @Tyagiquamar la tomó hace 5 días. Abiertoneeds-triage Stale
Dificultad 2/5 1-3 horas Aptitud para principiantes 68/100
open-telemetry/opentelemetry-cpp#4347 · 1 comentario ·
Los mantenedores suelen responder en 1 día
-
bug Stale triage/accepted
Dificultad 1/5 Menos de una hora Aptitud para principiantes 62/100
open-telemetry/opentelemetry-cpp#3109 · 2 comentarios ·
Los mantenedores suelen responder en 1 día
Todos los issues de open-telemetry/opentelemetry-cpp
Issues similares
-
bug iOS 🍎 ui/ux
Dificultad 2/5 1-3 horas Aptitud para principiantes 72/100
MerginMaps/mobile#4744 ·
Los mantenedores suelen responder en 1 día
-
Component: Ruby Type: bug
Dificultad 2/5 1-3 horas Aptitud para principiantes 74/100
Los mantenedores suelen responder en 1 día
-
Dificultad 1/5 Menos de una hora Aptitud para principiantes 88/100
Los mantenedores suelen responder en 3 días
-
Dificultad 1/5 Menos de una hora Aptitud para principiantes 92/100
kokkos/kokkos-kernels#3328 ·
Los mantenedores suelen responder en 1 día
-
bug needs triage tcp
Dificultad 2/5 1-3 horas Aptitud para principiantes 78/100
project-chip/connectedhomeip#74644 ·
Los mantenedores suelen responder en 1 día