The Elastic APM .NET Agent can leak sensitive HTTP header information when logging the details during an application error. Normally, the APM agent will sanitize sensitive HTTP header details before sending the information to the APM server. During an application error it is possible the headers will not be sanitized before being sent.
References
Link | Resource |
---|---|
https://discuss.elastic.co/t/elastic-apm-net-agent-1-10-0-security-update/274668 | Vendor Advisory |
https://www.elastic.co/community/security | Vendor Advisory |
Configurations
History
30 Nov 2023, 18:33
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:elastic:apm_.net_agent:*:*:*:*:*:*:*:* | |
CWE | CWE-532 | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 4.3 |
References | () https://www.elastic.co/community/security - Vendor Advisory | |
References | () https://discuss.elastic.co/t/elastic-apm-net-agent-1-10-0-security-update/274668 - Vendor Advisory |
22 Nov 2023, 03:36
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-11-22 02:15
Updated : 2024-02-05 00:22
NVD link : CVE-2021-22143
Mitre link : CVE-2021-22143
CVE.ORG link : CVE-2021-22143
JSON object : View
Products Affected
elastic
- apm_.net_agent