PT-2019-18669 · Elastic · Apm Agent For Python
Published
2019-08-22
·
Updated
2022-05-24
·
CVE-2019-7617
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Elastic APM agent for Python versions prior to 5.1.0
Description
The issue arises when the Elastic APM agent for Python is run as a CGI script, and a remote attacker can control the proxy header, leading to a variable name clash flaw. This flaw could allow an attacker to redirect collected APM data to a proxy of their choosing.
Recommendations
For versions prior to 5.1.0, update to version 5.1.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the proxy header to minimize the risk of exploitation.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apm Agent For Python