Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qqc5-rgcc-cjqh

Опубликовано: 18 мая 2021
Источник: github
Github: Прошло ревью
CVSS3: 2.4

Описание

Information Disclosure in go.elastic.co/apm

The Elastic APM agent for Go versions before 1.11.0 can leak sensitive HTTP header information when logging the details during an application panic. Normally, the APM agent will sanitize sensitive HTTP header details before sending the information to the APM server. During an application panic it is possible the headers will not be sanitized before being sent.

Пакеты

Наименование

go.elastic.co/apm

go
Затронутые версииВерсия исправления

< 1.11.0

1.11.0

EPSS

Процентиль: 22%
0.00073
Низкий

2.4 Low

CVSS3

Дефекты

CWE-532

Связанные уязвимости

CVSS3: 2.4
redhat
около 5 лет назад

The Elastic APM agent for Go versions before 1.11.0 can leak sensitive HTTP header information when logging the details during an application panic. Normally, the APM agent will sanitize sensitive HTTP header details before sending the information to the APM server. During an application panic it is possible the headers will not be sanitized before being sent.

CVSS3: 2.4
nvd
почти 5 лет назад

The Elastic APM agent for Go versions before 1.11.0 can leak sensitive HTTP header information when logging the details during an application panic. Normally, the APM agent will sanitize sensitive HTTP header details before sending the information to the APM server. During an application panic it is possible the headers will not be sanitized before being sent.

EPSS

Процентиль: 22%
0.00073
Низкий

2.4 Low

CVSS3

Дефекты

CWE-532