CVE-2021-22143

Published Nov 22, 2023

Last updated 5 months ago

Overview

Description
The Elastic APM .NET Agent can leak sensitive HTTP header information when logging the details during an application error. Normally, the APM agent will sanitize sensitive HTTP header details before sending the information to the APM server. During an application error it is possible the headers will not be sanitized before being sent.
Source
bressers@elastic.co
NVD status
Modified

Risk scores

CVSS 3.1

Type
Primary
Base score
4.3
Impact score
1.4
Exploitability score
2.8
Vector string
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Severity
MEDIUM

Weaknesses

bressers@elastic.co
CWE-200
nvd@nist.gov
CWE-532

Social media

Hype score
Not currently trending

Configurations