REDHAT-BUG-2452071: High severity OpenTelemetry OpenTelemetry Java Instrumentation vulnerability
OpenTelemetry Java Instrumentation provides OpenTelemetry auto-instrumentation and instrumentation libraries for Java. In versions prior to 2.26.1, the RMI instrumentation registered a custom endpoint that deserialized incoming data without applying serialization filters. On JDK version 16 and earlier, an attacker with network access to a JMX or RMI port on an instrumented JVM could exploit this to potentially achieve remote code execution. All three of the following conditions must be true to exploit this vulnerability: First, OpenTelemetry Java instrumentation is attached as a Java agent (-javaagent) on Java 16 or earlier. Second, JMX/RMI port has been explicitly configured via -Dcom.sun.management.jmxremote.port and is network-reachable. Third, gadget-chain-compatible library is present on the classpath. This results in arbitrary remote code execution with the privileges of the user running the instrumented JVM. For JDK >= 17, no action is required, but upgrading is strongly encouraged. For JDK < 17, upgrade to version 2.26.1 or later. As a workaround, set the system property -Dotel.instrumentation.rmi.enabled=false to disable the RMI integration.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
OpenTelemetry Java Instrumentationto a version that resolves this vulnerability.Fixed in 2.26.1 - Configuration
Set the system property `-Dotel.instrumentation.rmi.enabled=false` to disable the RMI integration (workaround).
OpenTelemetry Java Instrumentation -Dotel.instrumentation.rmi.enabled = false
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2452071?
The severity of REDHAT-BUG-2452071 is high, rated at 7.
How do I fix REDHAT-BUG-2452071?
To fix REDHAT-BUG-2452071, upgrade to OpenTelemetry Java Instrumentation version 2.26.1 or later.
What vulnerabilities does REDHAT-BUG-2452071 expose?
REDHAT-BUG-2452071 exposes a vulnerability related to improper deserialization of incoming data without serialization filters.
Which versions of OpenTelemetry are affected by REDHAT-BUG-2452071?
OpenTelemetry Java Instrumentation versions prior to 2.26.1 are affected by REDHAT-BUG-2452071.
What is the impact of not addressing REDHAT-BUG-2452071?
Not addressing REDHAT-BUG-2452071 could lead to potential security risks due to improper handling of serialized data in RMI.