VDB
Sign up
HIGH7.0

GHSA-v8pv-4842-x354

OpenTelemetry.Resources.Host vulnerable to arbitrary code execution via local PATH hijacking on macOS

Quick fix

GHSA-v8pv-4842-x354 — OpenTelemetry.Resources.Host: upgrade to the fixed version with the command below.

dotnet add package OpenTelemetry.Resources.Host --version 1.16.0-beta.2

Details

### Summary

The `OpenTelemetry.Resources.Host` NuGet package is affected by an untrusted search path vulnerability on macOS. The `host.id` resource attribute detector launches the `sh` and `ioreg` executables by bare name rather than by absolute path, so both are resolved through the `PATH` environment variable.

A local attacker who is less privileged than the host application, and who can influence `PATH` or write to a directory that appears in `PATH` ahead of the system directories, can have an arbitrary binary executed in the application's security context, resulting in local code execution/privilege escalation.

### Details

The implementation of the host detector macOS has always invoked `ioreg` and `sh` via their bare names since it was implemented by [open-telemetry/opentelemetry-dotnet-contrib#1631](https://github.com/open-telemetry/opentelemetry-dotnet-contrib/pull/1631).

The vulnerability was fixed by [open-telemetry/opentelemetry-dotnet-contrib#4760](https://github.com/open-telemetry/opentelemetry-dotnet-contrib/pull/4760) which executes `ioreg` directly using its absolute path.

### Impact

Applications running on **macOS** that use the `OpenTelemetry.Resources.Host` detector when an attacker who is *less privileged* than the application process can influence `PATH` or write to a `PATH` directory that precedes the system directories (e.g. a higher-privileged service with a user-writable directory in its search path, or a process inheriting an attacker-influenced environment). The attacker gains code execution in the application's security context through an attacker-controlled `ioreg` executable.

### Mitigation

This vulnerability only affect macOS hosts - Linux and Windows hosts are unaffected.

### Workarounds

None known.

### References

- [GHSA-9h8m-3fm2-qjrq](https://github.com/open-telemetry/opentelemetry-go/security/advisories/GHSA-9h8m-3fm2-qjrq) - [open-telemetry/opentelemetry-dotnet-contrib#4760](https://github.com/open-telemetry/opentelemetry-dotnet-contrib/pull/4760) - [CWE-426](https://cwe.mitre.org/data/definitions/426.html)

Are you affected?

Enter the version of the package you're using.

Affected packages

NuGet/OpenTelemetry.Resources.Host
Introduced in: 0Fixed in: 1.16.0-beta.2
Fixdotnet add package OpenTelemetry.Resources.Host --version 1.16.0-beta.2

References