First published: Wed Nov 22 2023(Updated: )
The Elastic APM .NET Agent can leak sensitive HTTP header information when logging the details during an application error. Normally, the APM agent will sanitize sensitive HTTP header details before sending the information to the APM server. During an application error it is possible the headers will not be sanitized before being sent.
Credit: bressers@elastic.co bressers@elastic.co
Affected Software | Affected Version | How to fix |
---|---|---|
Elastic APM .NET Agent | <1.10.0 | |
nuget/Elastic.Apm | <1.10.0 | 1.10.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-22143 is a vulnerability that allows the Elastic APM .NET Agent to leak sensitive HTTP header information during an application error.
If you are using the Elastic APM .NET Agent version up to and excluding 1.10.0, your sensitive HTTP header information may be leaked during an application error.
CVE-2021-22143 has a severity level of low with a CVSS score of 2.1.
To fix CVE-2021-22143, update your Elastic APM .NET Agent to version 1.10.0 or higher.
You can find more information about CVE-2021-22143 on the Elastic community security page, the National Vulnerability Database (NVD), and the Elastic Discuss forum.