CyberRota Analysis
AI-GeneratedApplications utilizing vulnerable versions of micrometer-registry-statsd or micrometer-core, particularly with Datadog or Etsy StatsD flavors, are susceptible to injection and spoofing attacks due to the handling of untrusted input for metrics data. Attackers can exploit this vulnerability to inject line terminators, enabling them to spoof arbitrary metrics and manipulate log entries, potentially compromising the integrity of monitoring and logging systems. Organizations using these libraries for metrics instrumentation should prioritize remediation to safeguard against potential data integrity issues.
Original NVD Description
Using untrusted, non-normalized input as-is for metrics data (such as metric names, tag keys, or tag values) is a dangerous antipattern that general-purpose instrumentation should never perform. Micrometer 1.17.0 Micrometer 1.16.0 - 1.16.6 Micrometer 1.15.0 - 1.15.12 Micrometer 1.14.0 - 1.14.16 Micrometer 1.9.18 and earlier