THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-rwqx-fvqh-6wm4 (medium) — OpenTelemetry Java Instrumentation: JDBC Auto-Instrumentation Logging Clear-Text Passwords

[GHSA] GHSA-rwqx-fvqh-6wm4 (medium) — OpenTelemetry Java Instrumentation: JDBC Auto-Instrumentation Logging Clear-Text Passwords

medgithub_advisoriesPublished 2026-07-29

GHSA-rwqx-fvqh-6wm4 Severity: medium CVE: CVE-2026-54704

OpenTelemetry Java Instrumentation: JDBC Auto-Instrumentation Logging Clear-Text Passwords

OpenTelemetry Java Instrumentation JDBC auto-instrumentation may fail to sanitize passwords in SQL CONNECT statements when the password is double-quoted. As a result, clear-text database passwords can be added to trace span attributes and exported to

Indicators of compromise

Original source: https://github.com/advisories/GHSA-rwqx-fvqh-6wm4