First published: Thu Aug 22 2019(Updated: )
When the Elastic APM agent for Python versions before 5.1.0 is run as a CGI script, there is a variable name clash flaw if a remote attacker can control the proxy header. This could result in an attacker redirecting collected APM data to a proxy of their choosing.
Credit: bressers@elastic.co bressers@elastic.co
Affected Software | Affected Version | How to fix |
---|---|---|
pip/elastic-apm | <5.1.0 | 5.1.0 |
Elastic Apm Agent | <5.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-7617 is a vulnerability in the Elastic APM agent for Python versions before 5.1.0, which allows a remote attacker to redirect collected APM data to a proxy of their choosing.
CVE-2019-7617 affects Elastic APM agent for Python versions before 5.1.0 when it is run as a CGI script.
CVE-2019-7617 has a severity rating of 7.2 (high).
To fix CVE-2019-7617, you should update the Elastic APM agent for Python to version 5.1.0 or later.
You can find more information about CVE-2019-7617 on the NVD (National Vulnerability Database) website or the Elastic website.