Junglewise Threat Intelligence

OpenTelemetry instrumentation remote code execution in module loader

Severity: low · CVSS 3.1 · Published 2023-08-09

Vendors: Datadog, Opentelemetry, npm.

Executive brief

OpenTelemetry's instrumentation library dynamically generates wrapper modules to intercept and monitor application code. When an application passes user-controlled input directly to an import() function, an attacker can inject malicious module paths, leading to remote code execution on the affected system. This affects applications using the experimental module loader feature with untrusted input.

Technical details

The vulnerability exists in the import-in-the-middle loader used by @opentelemetry/instrumentation, which dynamically generates wrapper modules at runtime. The wrapper uses an unvalidated module specifier to load the original module, creating a code injection path when user-supplied input is passed to import(). An attacker can craft a malicious module specifier to load arbitrary code. The vulnerability requires the application to use the experimental loader (--experimental-loader or --loader flags) and pass untrusted input to import(), but requires no authentication or user interaction. This was patched in @opentelemetry/instrumentation 0.41.2 and import-in-the-middle 1.4.2.

Affected products

  • OpenTelemetry instrumentation 0.40.0 to before 0.41.2
  • Datadog import-in-the-middle before 1.4.2

Timeline

  • 2023-08-09: disclosed
  • 2023-08-09: patched: @opentelemetry/instrumentation 0.41.2 and import-in-the-middle 1.4.2

References