reject grouping file-exporter traversal through Windows path separators
fixed in public source; rollout not reverified
details
Finding IDs
F-OTELCOLLECTORCONTRIB-001
Status
fixed in public source; rollout not reverified
Disclosure date
Note
PR #49195 normalizes Windows backslashes before path containment checks and adds traversal tests. This matches the reported fileexporter path, not the separate Collector snappy issue. Release inclusion and a public advisory assignment were not independently checked.
F-OTELCOLLECTORCONTRIB-001: File / path escapes. Windows path handling escapes the intended file boundary. Reviewed 24 Sep 2026. Mechanism assessed by 1seal.
Security area (1seal assessment): Authorization. A grouping value must not select an output file outside the configured directory. Reviewed 23 Sep 2026.
This identifier groups recorded evidence; it is not an additional CVE, independent-vulnerability count or guarantee of vendor confirmation. Fixed code, released versions, attribution and independent discovery are distinct claims. Absent metadata means not recorded, not disproved. Counting rules.