The Elastic APM .NET Agent can leak sensitive HTTP header information when logging the details during an application error. Normally, the APM agent will sanitize sensitive HTTP header details before sending the information to the APM server. During an application error it is possible the headers will not be sanitized before being sent.
References
Link | Resource |
---|---|
https://discuss.elastic.co/t/elastic-apm-net-agent-1-10-0-security-update/274668 | Vendor Advisory |
https://www.elastic.co/community/security | Vendor Advisory |
https://discuss.elastic.co/t/elastic-apm-net-agent-1-10-0-security-update/274668 | Vendor Advisory |
https://www.elastic.co/community/security | Vendor Advisory |
Configurations
History
21 Nov 2024, 05:49
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 2.1 |
References | () https://discuss.elastic.co/t/elastic-apm-net-agent-1-10-0-security-update/274668 - Vendor Advisory | |
References | () https://www.elastic.co/community/security - Vendor Advisory |
30 Nov 2023, 18:33
Type | Values Removed | Values Added |
---|---|---|
First Time |
Elastic
Elastic apm .net Agent |
|
CPE | cpe:2.3:a:elastic:apm_.net_agent:*:*:*:*:*:*:*:* | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 4.3 |
CWE | CWE-532 | |
References | () https://discuss.elastic.co/t/elastic-apm-net-agent-1-10-0-security-update/274668 - Vendor Advisory | |
References | () https://www.elastic.co/community/security - Vendor Advisory |
22 Nov 2023, 03:36
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-11-22 02:15
Updated : 2024-11-21 05:49
NVD link : CVE-2021-22143
Mitre link : CVE-2021-22143
CVE.ORG link : CVE-2021-22143
JSON object : View
Products Affected
elastic
- apm_.net_agent