THREAT OPS › Threat News › [GHSA] GHSA-rwqx-fvqh-6wm4 (medium) — OpenTelemetry Java Instrumentation: JDBC Auto-Instrumentation Logging Clear-Text Passwords
[GHSA] GHSA-rwqx-fvqh-6wm4 (medium) — OpenTelemetry Java Instrumentation: JDBC Auto-Instrumentation Logging Clear-Text Passwords
GHSA-rwqx-fvqh-6wm4 Severity: medium CVE: CVE-2026-54704
OpenTelemetry Java Instrumentation: JDBC Auto-Instrumentation Logging Clear-Text Passwords
OpenTelemetry Java Instrumentation JDBC auto-instrumentation may fail to sanitize passwords in SQL CONNECT statements when the password is double-quoted. As a result, clear-text database passwords can be added to trace span attributes and exported to
Indicators of compromise
- CVE-2026-54704cve
Original source: https://github.com/advisories/GHSA-rwqx-fvqh-6wm4