Information exposure through an error message in Elastic APM .NET Agent - CVE-2021-22143

 

Information exposure through an error message in Elastic APM .NET Agent - CVE-2021-22143

Published: June 2, 2021


Vulnerability identifier: #VU53728
CSH Severity: Low
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-22143
CWE-ID: CWE-209
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to sensitive information.

The vulnerability exists due to Elastic APM .NET Agent leaks sensitive HTTP header information when logging the details during an application error. A remote attacker can intercept traffic sent to the APM server and gain access to potentially sensitive information, sent via HTTP headers.


Affected software

Elastic APM .NET Agent

How to mitigate CVE-2021-22143

Install updates from vendor's website.

Elastic APM .NET Agent - update to 1.10.0

External References

Related Security Bulletins