Skip to content

ALERT: Possible app crash for OpenTelemetry .NET versions 1.3.0 and prior #3629

@CodeBlanch

Description

@CodeBlanch

What is the impact?

An application crash can be caused by adding ActivityEvents or ActivityLinks with tags and using one of the exporters provided by the opentelemetry-dotnet project. Adding an ActivityEvent or ActivityLink may be performed by your code or any instrumentation package you reference (e.g., OpenTelemetry.Instrumentation.HttpClient).

First reported by #3593.

Who this will impact?

Applications referencing System.Diagnositcs.DiagnosticSource version 7.0 - either directly or via an indirect dependency - plus version 1.3.0 or prior of the following OpenTelemetry exporters can experience the application crash:

  • OpenTelemetry.Exporter.Jaeger versions 1.3.0 or lower
  • OpenTelemetry.Exporter.OpenTelemetryProtocol versions 1.3.0 or lower
  • OpenTelemetry.Exporter.Zipkin versions 1.3.0 or lower

What action should I take?

Upgrade the affected packages to version 1.3.1 or later.

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions