Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-r562-m862-63w3

Опубликовано: 09 дек. 2021
Источник: github
Github: Прошло ревью
CVSS3: 7.8

Описание

APM Java Agent Local Privilege Escalation

A local privilege escalation issue was found with the APM Java agent, where a user on the system could attach a malicious file to an application running with the APM Java agent. Using this vector, a malicious or compromised user account could use the agent to run commands at a higher level of permissions than they possess. This vulnerability affects users that have set up the agent via the attacher cli 3, the attach API 2, as well as users that have enabled the profiling_inferred_spans_enabled option

Пакеты

Наименование

elastic-apm

pip
Затронутые версииВерсия исправления

>= 1.10.0, < 1.27.0

1.27.0

EPSS

Процентиль: 9%
0.00033
Низкий

7.8 High

CVSS3

Дефекты

CWE-269

Связанные уязвимости

CVSS3: 7.8
nvd
около 4 лет назад

A local privilege escalation issue was found with the APM Java agent, where a user on the system could attach a malicious file to an application running with the APM Java agent. Using this vector, a malicious or compromised user account could use the agent to run commands at a higher level of permissions than they possess. This vulnerability affects users that have set up the agent via the attacher cli 3, the attach API 2, as well as users that have enabled the profiling_inferred_spans_enabled option

EPSS

Процентиль: 9%
0.00033
Низкий

7.8 High

CVSS3

Дефекты

CWE-269