When the Elastic APM agent for Python versions before 5.1.0 is run as a CGI script, there is a variable name clash flaw if a remote attacker can control the proxy header. This could result in an attacker redirecting collected APM data to a proxy of their choosing.
Advisories
Source ID Title
EUVD EUVD EUVD-2019-0048 When the Elastic APM agent for Python versions before 5.1.0 is run as a CGI script, there is a variable name clash flaw if a remote attacker can control the proxy header. This could result in an attacker redirecting collected APM data to a proxy of their choosing.
Github GHSA Github GHSA GHSA-22jh-6gx8-f944 Elastic APM agent for Python client CGI proxy redirection flaw
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: elastic

Published:

Updated: 2024-08-04T20:54:28.320Z

Reserved: 2019-02-07T00:00:00

Link: CVE-2019-7617

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2019-08-22T17:15:10.357

Modified: 2024-11-21T04:48:24.660

Link: CVE-2019-7617

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses