CVE-2021-22143: Elastic APM .NET Agent information disclosure
The Elastic APM .NET Agent can leak sensitive HTTP header information when logging the details during an application error. Normally, the APM agent will sanitize sensitive HTTP header details before sending the information to the APM server. During an application error it is possible the headers will not be sanitized before being sent.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-22143?
CVE-2021-22143 is a vulnerability that allows the Elastic APM .NET Agent to leak sensitive HTTP header information during an application error.
How does CVE-2021-22143 affect me?
If you are using the Elastic APM .NET Agent version up to and excluding 1.10.0, your sensitive HTTP header information may be leaked during an application error.
What is the severity of CVE-2021-22143?
CVE-2021-22143 has a severity level of low with a CVSS score of 2.1.
How can I fix CVE-2021-22143?
To fix CVE-2021-22143, update your Elastic APM .NET Agent to version 1.10.0 or higher.
Where can I find more information about CVE-2021-22143?
You can find more information about CVE-2021-22143 on the Elastic community security page, the National Vulnerability Database (NVD), and the Elastic Discuss forum.