CVE-2026-104872 OpenTelemetry JS Contrib 数据库用户名信息泄露漏洞
影响遥测数据泄露数据库账号名,暴露服务拓扑与账号命名规律
OpenTelemetry JavaScript Contrib 是用于从 JavaScript 应用采集遥测数据的插桩库集合。在多个数据库插桩包中,程序会把数据库连接用户名作为 db.user 属性附加到每一次被插桩的数据库操作上。该属性默认开启且不受 enhancedDatabaseReporting 等开关控制,导致后端可观测性平台收到数据库账号名。
影响范围
漏洞详情
漏洞类型为信息泄露。成因是相关插桩包在生成 span 时默认写入 db.user 属性,未提供关闭或脱敏选项。利用方式并非主动攻击,而是任何能访问所配置遥测后端的人都能读取这些账号名,进而推断服务拓扑、角色或环境信息以及账号命名规律。
利用条件与风险
利用前提是应用使用受影响插桩包并启用了遥测上报,且后端数据可被第三方或低权限人员查看。实战风险为中等,主要造成敏感信息暴露,本身不直接导致代码执行或数据篡改。
修复建议
升级到修复版本:@opentelemetry/instrumentation-cassandra-driver 0.66.0、instrumentation-knex 0.65.0、instrumentation-mongoose/mysql/mysql2 0.67.0、instrumentation-oracledb 0.46.0、instrumentation-pg 0.73.0、instrumentation-tedious 0.40.0。临时缓解可限制遥测后端访问权限或对上报数据中的 db.user 属性进行过滤脱敏。
OpenTelemetry JavaScript Contrib provides instrumentation libraries for collecting telemetry from JavaScript applications. Prior to versions 0.66.0 of @opentelemetry/instrumentation-cassandra-driver, 0.65.0 of @opentelemetry/instrumentation-knex, 0.67.0 of @opentelemetry/instrumentation-mongoose, @opentelemetry/instrumentation-mysql, and @opentelemetry/instrumentation-mysql2, 0.46.0 of @opentelemetry/instrumentation-oracledb, 0.73.0 of @opentelemetry/instrumentation-pg, and 0.40.0 of @opentelemetry/instrumentation-tedious, the packages add the database connection username to every instrumented database operation as the db.user span attribute. The attribute is emitted by default and is not controlled by enhancedDatabaseReporting or another opt-in setting. Configured observability backends therefore receive database account names that may expose service topology, role or environment information, and account naming patterns. This issue is fixed in versions 0.66.0, 0.65.0, 0.67.0, 0.46.0, 0.73.0, and 0.40.0 of the respective packages.