Skip to content

com.google.cloud.opentelemetry:auto-exporter is logging the service account access token #430

@vgonsalv

Description

@vgonsalv

When using the auto-exporter along-side the standard OpenTelmetry Java agent (link), the Service Account access token is being logged.

This is a security issue, as it allows anyone with access to the logs to be able to impersonate the service.

The desired fix is that this token not be logged at all.

Metadata

Metadata

Assignees

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions