Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-37941

Опубликовано: 08 дек. 2021
Источник: nvd
CVSS3: 7.8
CVSS2: 4.4
EPSS Низкий

Описание

A local privilege escalation issue was found with the APM Java agent, where a user on the system could attach a malicious file to an application running with the APM Java agent. Using this vector, a malicious or compromised user account could use the agent to run commands at a higher level of permissions than they possess. This vulnerability affects users that have set up the agent via the attacher cli 3, the attach API 2, as well as users that have enabled the profiling_inferred_spans_enabled option

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:elastic:apm_agent:*:*:*:*:*:java:*:*
Версия от 1.10.0 (включая) до 1.26.0 (включая)

EPSS

Процентиль: 9%
0.00033
Низкий

7.8 High

CVSS3

4.4 Medium

CVSS2

Дефекты

CWE-269
CWE-269

Связанные уязвимости

CVSS3: 7.8
github
около 4 лет назад

APM Java Agent Local Privilege Escalation

EPSS

Процентиль: 9%
0.00033
Низкий

7.8 High

CVSS3

4.4 Medium

CVSS2

Дефекты

CWE-269
CWE-269