CyberRota Analysis
AI-GeneratedApplications utilizing a vulnerable version of io.micrometer:micrometer-tracing-bridge-brave with W3C baggage propagation enabled are susceptible to denial of service due to unbounded object allocation when processing incoming baggage headers. This vulnerability can be exploited by attackers sending requests with excessively large baggage headers, leading to increased CPU usage and potential application crashes from OutOfMemoryError. Organizations using affected versions, particularly those processing untrusted input, should prioritize patching to mitigate this risk.
Original NVD Description
An application using Micrometer Tracing with W3C baggage propagation in the Brave bridge is vulnerable to denial of service (DoS) due to unbounded object allocation when extracting incoming baggage headers. Micrometer Tracing 1.7.0 Micrometer Tracing 1.6.0 - 1.6.6 Micrometer Tracing 1.5.0 - 1.5.12 Micrometer Tracing 1.4.13 and earlier