CVE-2021-22133
Title: Elastic Apm Agent Information Disclosure
Information Disclosure
Proof Of Concept
No public PoC currently indexed for CVE-2021-22133.
CWE Category
CWE-532
Published Date
Feb 10, 2021
Modified Date
Nov 21, 2024
Exploit Status
Not Found
Score
2.4
CVSS v3.1
Exploit Probability (EPSS)
0.07%
Vulnerability Summary
CVE-2021-22133: The Elastic APM agent for Go versions before 1.11.0 can leak sensitive HTTP header information when logging the details during an application panic. Normally, the APM agent will sanitize sensitive HTTP header details before sending the information to the APM server. During an application panic it is possible the headers will not be sanitized before being sent.
CVSS v3.1
Source Entity
[email protected]
Severity
LOW
2.4
Attack Vector
ADJACENT_NETWORK
Complexity
LOW
Privileges
N/A
Interaction
NONE
Confidentiality
N/A
Integrity
N/A
Availability
N/A
Scope
UNCHANGED
RAW VECTOR
CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
CVSS v2.0
Source Entity
[email protected]
Severity
LOW
2.7
Access Vector
N/A
Authentication
N/A
RAW VECTOR
AV:A/AC:L/Au:S/C:P/I:N/A:N
Associated Attack Patterns (CAPEC)
Total: PatternsNo specific attack patterns mapped.
Likelihood
Severity
Page /
CVE-2021-22133 Exploits & PoCs (Proof Of Concept)
No public PoCs found in our database for this CVE.
MODIFIED
Vulnerability data or affected products updated.
PUBLISHED
Vulnerability first announced in NVD.
Attack Vector Matrix
Access Vector
ADJACENT_NETWORK
Complexity
LOW
Privileges
N/A
Interaction
NONE
CVSS Vector String
CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
Affected Stack
No specific products linked.