REDHAT-BUG-1942553: Low severity elastic apm agent for go vulnerability
The Elastic APM agent for Go versions before 1.11.0 can leak sensitive HTTP header information when logging the details during an application panic. Normally, the APM agent will sanitize sensitive HTTP header details before sending the information to the APM server. During an application panic it is possible the headers will not be sanitized before being sent.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1942553?
The severity of REDHAT-BUG-1942553 is considered important due to the potential leakage of sensitive HTTP header information.
How do I fix REDHAT-BUG-1942553?
To fix REDHAT-BUG-1942553, upgrade the Elastic APM agent for Go to version 1.11.0 or later.
What versions of Elastic APM agent for Go are affected by REDHAT-BUG-1942553?
Versions of Elastic APM agent for Go before 1.11.0 are affected by REDHAT-BUG-1942553.
What type of information is leaked in REDHAT-BUG-1942553?
REDHAT-BUG-1942553 can leak sensitive HTTP header information during application panic events.
Is there a specific environment where REDHAT-BUG-1942553 is a risk?
Yes, REDHAT-BUG-1942553 poses a risk in any environment using the affected versions of Elastic APM agent for Go.