<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Jaeger</title>
  <link>https://cvedaily.com/pages/tags/jaeger.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/jaeger.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Jaeger</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:53 +0000</lastBuildDate>
  <item>
    <title>[Medium] CVE-2026-41078 – OpenTelemetry dotnet is a dotnet telemetry framework. In 1.6.0-rc.1 and earlier,...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41078</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41078</guid>
    <pubDate>Thu, 23 Apr 2026 19:17:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-41078</strong></p>
  <p>OpenTelemetry dotnet is a dotnet telemetry framework. In 1.6.0-rc.1 and earlier, OpenTelemetry.Exporter.Jaeger may allow sustained memory pressure when the internal pooled-list sizing grows based on a large observed span/tag set and that enlarged size is reused for subsequent allocations. Under high-cardinality or attacker-influenced telemetry input, this can increase memory consumption and poten…</p>
  <p><strong>CVSS:</strong> 5.9 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41078">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-40894 – OpenTelemetry dotnet is a dotnet telemetry framework. In OpenTelemetry.Api 0.5.0...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40894</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40894</guid>
    <pubDate>Thu, 23 Apr 2026 19:17:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-40894</strong></p>
  <p>OpenTelemetry dotnet is a dotnet telemetry framework. In OpenTelemetry.Api 0.5.0-beta.2 to 1.15.2 and OpenTelemetry.Extensions.Propagators 1.3.1 to 1.15.2, The implementation details of the baggage, B3 and Jaeger processing code in the OpenTelemetry.Api and OpenTelemetry.Extensions.Propagators NuGet packages can allocate excessive memory when parsing which could create a potential denial of servi…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-789</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40894">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-41117 – Stack traces in Grafana's Explore Traces view can be rendered as raw HTML, and t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-41117</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-41117</guid>
    <pubDate>Thu, 12 Feb 2026 09:16:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-41117</strong></p>
  <p>Stack traces in Grafana's Explore Traces view can be rendered as raw HTML, and thus inject malicious JavaScript in the browser. This would require malicious JavaScript to be entered into the stack trace field.  Only datasources with the Jaeger HTTP API appear to be affected; Jaeger gRPC and Tempo do not appear affected whatsoever.</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-41117">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-2842 – A flaw was found in the Tempo Operator. When the Jaeger UI Monitor Tab functiona...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-2842</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-2842</guid>
    <pubDate>Wed, 02 Apr 2025 12:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-2842</strong></p>
  <p>A flaw was found in the Tempo Operator. When the Jaeger UI Monitor Tab functionality is enabled in a Tempo instance managed by the Tempo Operator, the Operator creates a ClusterRoleBinding for the Service Account of the Tempo instance to grant the cluster-monitoring-view ClusterRole. This can be exploited if a user has 'create' permissions on TempoStack and 'get' permissions on Secret in a namesp…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-2842">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-4009 – Replay Attack

in ABB, Busch-Jaeger, FTS Display (version 1.00) and BCU (version...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-4009</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-4009</guid>
    <pubDate>Wed, 05 Jun 2024 18:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-4009</strong></p>
  <p>Replay Attack  in ABB, Busch-Jaeger, FTS Display (version 1.00) and BCU (version 1.3.0.33) allows attacker to capture/replay KNX telegram to local KNX Bus-System</p>
  <p><strong>CVSS:</strong> 9.2 · <strong>CWE:</strong> CWE-294</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-4009">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-4008 – FDSK Leak in ABB, Busch-Jaeger, FTS Display (version 1.00) and BCU (version 1.3...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-4008</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-4008</guid>
    <pubDate>Wed, 05 Jun 2024 18:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-4008</strong></p>
  <p>FDSK Leak in ABB, Busch-Jaeger, FTS Display (version 1.00) and BCU (version 1.3.0.33) allows attacker to take control via access to local KNX Bus-System</p>
  <p><strong>CVSS:</strong> 9.6 · <strong>CWE:</strong> CWE-497</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-4008">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-36656 – Cross Site Scripting (XSS) vulnerability in Jaegertracing Jaeger UI before v.1.3...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-36656</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-36656</guid>
    <pubDate>Mon, 17 Jul 2023 16:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-36656</strong></p>
  <p>Cross Site Scripting (XSS) vulnerability in Jaegertracing Jaeger UI before v.1.31.0 allows a remote attacker to execute arbitrary code via the KeyValuesTable component.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-36656">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-22272 – The vulnerability origins in the commissioning process where an attacker of the ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-22272</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-22272</guid>
    <pubDate>Mon, 27 Sep 2021 14:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-22272</strong></p>
  <p>The vulnerability origins in the commissioning process where an attacker of the ControlTouch can enter a serial number in a specific way to transfer the device virtually into her/his my.busch-jaeger.de or mybuildings.abb.com profile. A successful attacker can observe and control a ControlTouch remotely under very specific circumstances. The issue is fixed in the cloud side of the system. No firmw…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-22272">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-10750 – Sensitive information written to a log file vulnerability was found in jaegertra...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-10750</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-10750</guid>
    <pubDate>Fri, 19 Jun 2020 20:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-10750</strong></p>
  <p>Sensitive information written to a log file vulnerability was found in jaegertracing/jaeger before version 1.18.1 when the Kafka data store is used. This flaw allows an attacker with access to the container's log file to discover the Kafka credentials.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-10750">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-19107 – The Configuration pages in ABB Telephone Gateway TG/S 3.2 and Busch-Jaeger 6186/...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-19107</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-19107</guid>
    <pubDate>Wed, 22 Apr 2020 15:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-19107</strong></p>
  <p>The Configuration pages in ABB Telephone Gateway TG/S 3.2 and Busch-Jaeger 6186/11 Telefon-Gateway for user profiles and services transfer the password in plaintext (although hidden when displayed).</p>
  <p><strong>CVSS:</strong> 6.2 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-19107">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2019-19106 – Improper implementation of Access Control in ABB Telephone Gateway TG/S 3.2 and ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-19106</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-19106</guid>
    <pubDate>Wed, 22 Apr 2020 15:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2019-19106</strong></p>
  <p>Improper implementation of Access Control in ABB Telephone Gateway TG/S 3.2 and Busch-Jaeger 6186/11 Telefon-Gateway allows an unauthorized user to access data marked as restricted, such as viewing or editing user profiles and application settings.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-19106">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-19105 – The backup function in ABB Telephone Gateway TG/S 3.2 and Busch-Jaeger 6186/11 T...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-19105</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-19105</guid>
    <pubDate>Wed, 22 Apr 2020 15:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-19105</strong></p>
  <p>The backup function in ABB Telephone Gateway TG/S 3.2 and Busch-Jaeger 6186/11 Telefon-Gateway saves the current settings and configuration of the application, including credentials of existing user accounts and other configuration's credentials in plaintext.</p>
  <p><strong>CVSS:</strong> 6.2 · <strong>CWE:</strong> CWE-256</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-19105">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2019-19104 – The web server in ABB Telephone Gateway TG/S 3.2 and Busch-Jaeger 6186/11 Telefo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-19104</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-19104</guid>
    <pubDate>Wed, 22 Apr 2020 15:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2019-19104</strong></p>
  <p>The web server in ABB Telephone Gateway TG/S 3.2 and Busch-Jaeger 6186/11 Telefon-Gateway allows access to different endpoints of the application without authenticating by accessing a specific uniform resource locator (URL) , violating the access-control (ACL) rules. This issue allows obtaining sensitive information that may aid in further attacks and privilege escalation.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-19104">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2018-19578 – GitLab EE, version 11.5 before 11.5.1, is vulnerable to an insecure object refer...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-19578</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-19578</guid>
    <pubDate>Wed, 10 Jul 2019 17:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2018-19578</strong></p>
  <p>GitLab EE, version 11.5 before 11.5.1, is vulnerable to an insecure object reference issue that permits a user with Reporter privileges to view the Jaeger Tracing Operations page.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-285</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-19578">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
