PT-2023-12039 · Elastic · Apm .Net Agent

Published

2023-11-22

·

Updated

2023-11-30

·

CVE-2021-22143

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Elastic APM .NET Agent (affected versions not specified)
Description The issue concerns the Elastic APM .NET Agent leaking sensitive HTTP header information when logging application error details. Normally, the agent sanitizes sensitive HTTP header details before sending them to the APM server. However, during an application error, it is possible that the headers will not be sanitized before being sent.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Insertion into Log File

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2021-22143
GHSA-HX93-GC73-5RPR

Affected Products

Apm .Net Agent