« Volver al listado

CVE-2024-38525

Estado: AplazadaAlta (7.5)—

dd-trace-cpp is the Datadog distributed tracing for C++. When the library fails to extract trace context due to malformed unicode, it logs the list of audited headers and their values using the `nlohmann` JSON library. However, due to the way the JSON library is invoked, it throws an uncaught exception, which results in a crash. This vulnerability has been patched in version 0.2.2.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2024-38525",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2024-38525",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "yes"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-07-02T15:43:21.179262Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security-advisories@github.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "security-advisories@github.com",
      "affectedData": [
        {
          "vendor": "DataDog",
          "product": "dd-trace-cpp",
          "versions": [
            {
              "status": "affected",
              "version": ">= 0.1.12, < 0.2.2"
            }
          ]
        }
      ]
    },
    {
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "affectedData": [
        {
          "cpes": [
            "cpe:2.3:a:datadoghq:dd-trace-cpp:*:*:*:*:*:*:*:*"
          ],
          "vendor": "datadoghq",
          "product": "dd-trace-cpp",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "0.1.13",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "0",
              "lessThan": "0.2.2",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unknown"
        }
      ]
    }
  ],
  "published": "2024-06-28T22:15:02.567",
  "references": [
    {
      "url": "https://github.com/DataDog/dd-trace-cpp/releases/tag/v0.2.2",
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/DataDog/dd-trace-cpp/security/advisories/GHSA-rf3p-mg22-qv6w",
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/DataDog/dd-trace-cpp/releases/tag/v0.2.2",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://github.com/DataDog/dd-trace-cpp/security/advisories/GHSA-rf3p-mg22-qv6w",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security-advisories@github.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-20"
        },
        {
          "lang": "en",
          "value": "CWE-248"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "dd-trace-cpp is the Datadog distributed tracing for C++. When the library fails to extract trace context due to malformed unicode, it logs the list of audited headers and their values using the `nlohmann` JSON library. However, due to the way the JSON library is invoked, it throws an uncaught exception, which results in a crash. This vulnerability has been patched in version 0.2.2."
    },
    {
      "lang": "es",
      "value": "dd-trace-cpp es el seguimiento distribuido de Datadog para C++. Cuando la librería no puede extraer el contexto de seguimiento debido a un Unicode con formato incorrecto, registra la lista de encabezados auditados y sus valores utilizando la librería JSON `nlohmann`. Sin embargo, debido a la forma en que se invoca la librería JSON, genera una excepción no detectada, lo que provoca un bloqueo. Esta vulnerabilidad ha sido parcheada en la versión 0.2.2."
    }
  ],
  "lastModified": "2026-06-17T07:40:28.293",
  "sourceIdentifier": "security-advisories@github.com"
}