Description
The Elastic APM agent for Go versions before 1.11.0 can leak sensitive HTTP header information when logging the details during an application panic. Normally, the APM agent will sanitize sensitive HTTP header details before sending the information to the APM server. During an application panic it is possible the headers will not be sanitized before being sent.
Published: 2021-02-10
Score: 2.4 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2021-1171 The Elastic APM agent for Go versions before 1.11.0 can leak sensitive HTTP header information when logging the details during an application panic. Normally, the APM agent will sanitize sensitive HTTP header details before sending the information to the APM server. During an application panic it is possible the headers will not be sanitized before being sent.
Github GHSA Github GHSA GHSA-qqc5-rgcc-cjqh Information Disclosure in go.elastic.co/apm
History

No history.

Subscriptions

Elastic Apm Agent
Redhat Openshift
cve-icon MITRE

Status: PUBLISHED

Assigner: elastic

Published:

Updated: 2024-08-03T18:30:24.014Z

Reserved: 2021-01-04T00:00:00.000Z

Link: CVE-2021-22133

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-02-10T19:15:12.090

Modified: 2024-11-21T05:49:34.183

Link: CVE-2021-22133

cve-icon Redhat

Severity : Low

Publid Date: 2021-02-04T00:00:00Z

Links: CVE-2021-22133 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses