CVE-2021-22143 Vulnerability Details

  /     /     /  

CVE-2021-22143 Metadata Quick Info

CVE Published: 22/11/2023 | CVE Updated: 11/10/2024 | CVE Year: 2021
Source: elastic | Vendor: Elastic | Product: Elastic APM .NET Agent
Status : PUBLISHED

CVE-2021-22143 Description

The Elastic APM .NET Agent can leak sensitive HTTP header information when logging the details during an application error. Normally, the APM agent will sanitize sensitive HTTP header details before sending the information to the APM server. During an application error it is possible the headers will not be sanitized before being sent.

Metrics

CVSS Version: 3.1 | Base Score: 2.1 LOW
Vector: CVSS:3.1/AV:A/AC:L/PR:H/UI:R/S:U/C:L/I:N/A:N

l➤ Exploitability Metrics:
    Attack Vector (AV)* ADJACENT_NETWORK
    Attack Complexity (AC)* LOW
    Privileges Required (PR)* HIGH
    User Interaction (UI)* REQUIRED
    Scope (S)* UNCHANGED

l➤ Impact Metrics:
    Confidentiality Impact (C)* LOW
    Integrity Impact (I)* NONE
    Availability Impact (A)* NONE

Weakness Enumeration (CWE)

CWE-ID: CWE-200
CWE Name: CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
Source: Elastic

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID:
CAPEC Description:


Source: NVD (National Vulnerability Database).