@opentelemetry/instrumentation-cassandra-driver is vulnerable to Information Disclosure
58
Medium Risk
These OpenTelemetry database instrumentations record the database connection username as the db.user span attribute on every instrumented operation, unconditionally and without an opt-in flag such as enhancedDatabaseReporting. The attribute is exported to every configured observability backend, which can reveal service-account names, role-encoded usernames, and account naming patterns useful for privilege inference or credential enumeration. The fix stops emitting db.user by default and aligns database attribute emission with the stable attribute set.
You are affected if you are using a version that falls within the vulnerable range and export OpenTelemetry spans from instrumented database operations to an observability backend.
@opentelemetry/instrumentation-cassandra-driver is vulnerable to Information Disclosure in versions 0.23.0 - 0.65.0.
Upgrade the @opentelemetry/instrumentation-cassandra-driver library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.