Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-hx93-gc73-5rpr: Exposure of Sensitive Information in Elastic APM .NET Agent

The Elastic APM .NET Agent can leak sensitive HTTP header information when logging the details during an application error. Normally, the APM agent will sanitize sensitive HTTP header details before sending the information to the APM server. During an application error it is possible the headers will not be sanitized before being sent.

ghsa
#git

Exposure of Sensitive Information in Elastic APM .NET Agent

Low severity GitHub Reviewed Published Nov 22, 2023 to the GitHub Advisory Database • Updated Nov 22, 2023

Related news

CVE-2021-22143: Elastic APM .NET Agent 1.10.0 Security Update

The Elastic APM .NET Agent can leak sensitive HTTP header information when logging the details during an application error. Normally, the APM agent will sanitize sensitive HTTP header details before sending the information to the APM server. During an application error it is possible the headers will not be sanitized before being sent.

CVE-2022-38775: Security issues

An issue was discovered in the rollback feature of Elastic Endpoint Security for Windows, which could allow unprivileged users to elevate their privileges to those of the LocalSystem account.

CVE-2022-23712: Security issues

A Denial of Service flaw was discovered in Elasticsearch. Using this vulnerability, an unauthenticated attacker could forcibly shut down an Elasticsearch node with a specifically formatted network request.