Описание
The Elastic APM .NET Agent can leak sensitive HTTP header information when logging the details during an application error. Normally, the APM agent will sanitize sensitive HTTP header details before sending the information to the APM server. During an application error it is possible the headers will not be sanitized before being sent.
Ссылки
- Vendor Advisory
- Vendor Advisory
- Vendor Advisory
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 1.10.0 (исключая)
cpe:2.3:a:elastic:apm_.net_agent:*:*:*:*:*:*:*:*
EPSS
Процентиль: 42%
0.00202
Низкий
2.1 Low
CVSS3
4.3 Medium
CVSS3
Дефекты
CWE-200
CWE-532
Связанные уязвимости
CVSS3: 2.1
github
около 2 лет назад
Exposure of Sensitive Information in Elastic APM .NET Agent
EPSS
Процентиль: 42%
0.00202
Низкий
2.1 Low
CVSS3
4.3 Medium
CVSS3
Дефекты
CWE-200
CWE-532