PT-2023-12039 · Elastic · Apm .Net Agent

CVE-2021-22143

·

Publicado

2023-11-22

·

Atualizado

2023-11-30

CVSS v3.1

4.3

Média

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Elastic APM .NET Agent (affected versions not specified)
Description The issue concerns the Elastic APM .NET Agent leaking sensitive HTTP header information when logging application error details. Normally, the agent sanitizes sensitive HTTP header details before sending them to the APM server. However, during an application error, it is possible that the headers will not be sanitized before being sent.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Insertion into Log File

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2021-22143
GHSA-HX93-GC73-5RPR

Produtos afetados

Apm .Net Agent