GHSA-hx93-gc73-5rpr

Suggest an improvement
Source
https://github.com/advisories/GHSA-hx93-gc73-5rpr
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/11/GHSA-hx93-gc73-5rpr/GHSA-hx93-gc73-5rpr.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-hx93-gc73-5rpr
Aliases
Published
2023-11-22T03:30:19Z
Modified
2024-02-16T07:56:44.662292Z
Severity
  • 2.1 (Low) CVSS_V3 - CVSS:3.1/AV:A/AC:L/PR:H/UI:R/S:U/C:L/I:N/A:N CVSS Calculator
Summary
Exposure of Sensitive Information in Elastic APM .NET Agent
Details

The Elastic APM .NET Agent can leak sensitive HTTP header information when logging the details during an application error. Normally, the APM agent will sanitize sensitive HTTP header details before sending the information to the APM server. During an application error it is possible the headers will not be sanitized before being sent.

Database specific
{
    "nvd_published_at": "2023-11-22T02:15:41Z",
    "cwe_ids": [
        "CWE-200",
        "CWE-532"
    ],
    "severity": "LOW",
    "github_reviewed": true,
    "github_reviewed_at": "2023-11-22T20:56:15Z"
}
References

Affected packages

NuGet / Elastic.Apm

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.10.0

Affected versions

0.*

0.0.1-alpha
0.0.1
0.0.2-alpha

1.*

1.0.0-beta1
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
1.2.0
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.9.0