CVE-2021-22143 – elastic.apm
Package
Manager: nuget
Name: elastic.apm
Vulnerable Version: >=0 <1.10.0
Severity
Level: Low
CVSS v3.1: CVSS:3.1/AV:A/AC:L/PR:H/UI:R/S:U/C:L/I:N/A:N
CVSS v4.0: CVSS:4.0/AV:A/AC:L/AT:P/PR:H/UI:P/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
EPSS: 0.00202 pctl0.42525
Details
Exposure of Sensitive Information in Elastic APM .NET Agent The Elastic APM .NET Agent can leak sensitive HTTP header information when logging the details during an application error. Normally, the APM agent will sanitize sensitive HTTP header details before sending the information to the APM server. During an application error it is possible the headers will not be sanitized before being sent.
Metadata
Created: 2023-11-22T03:30:19Z
Modified: 2023-11-22T20:56:15Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/11/GHSA-hx93-gc73-5rpr/GHSA-hx93-gc73-5rpr.json
CWE IDs: ["CWE-200", "CWE-532"]
Alternative ID: GHSA-hx93-gc73-5rpr
Finding: F017
Auto approve: 1