Skip to content

Review, test and ensure TraceState,Baggage parsing is defensive #2757

@cijothomas

Description

@cijothomas

OpenTelemetry instrumentations rely on Propagators to parse incoming headers and extract Context (TraceContext, Baggage). Opening an issue to make sure these paths are sufficiently covered by tests.

Otel .NET published this advisory earlier today, where malformed tracestate header could be used by a bad actor and cause service to go down.
GHSA-8785-wc3w-h8q6

Metadata

Metadata

Assignees

Labels

A-commonArea:common issues that not related to specific pillarbaggagecontextpriority:p1Critical issues and bugs. Highest priority.

Type

Projects

No projects

Milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions