CVE-2021-22143
Last modified
CVE-2021-22143 is a medium-severity vulnerability rated 4.3/10 on the CVSS scale. The Elastic APM .NET Agent can leak sensitive HTTP header information when logging the details during an application error. Normally, the APM agent will sanitize sensitive HTTP header details before sending the information to the APM server. EPSS estimates a 0.61% chance of exploitation in the next 30 days.
Description
The Elastic APM .NET Agent can leak sensitive HTTP header information when logging the details during an application error. Normally, the APM agent will sanitize sensitive HTTP header details before sending the information to the APM server. During an application error it is possible the headers will not be sanitized before being sent.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Elastic | Apm .Net Agent | < 1.10.0 |
References
- https://www.elastic.co/community/securityVendor Advisory
- https://www.elastic.co/community/securityVendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-22143?
How severe is CVE-2021-22143?
How do I fix CVE-2021-22143?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-22138In Logstash versions after 6.4.0 and before 6.8.15 and 7.12.…3.7
- CVE-2021-22139Kibana versions before 7.12.1 contain a denial of service vu…6.5
- CVE-2021-2214Vulnerability in the Oracle WebLogic Server product of Oracl…4.4
- CVE-2021-22140Elastic App Search versions after 7.11.0 and before 7.12.0 c…7.5
- CVE-2021-22141An open redirect flaw was found in Kibana versions before 7.…6.1
- CVE-2021-22142Kibana contains an embedded version of the Chromium browser …8.8
- CVE-2021-22144In Elasticsearch versions before 7.13.3 and 6.8.17 an uncont…6.5
- CVE-2021-22145A memory disclosure vulnerability was identified in Elastics…6.5
- CVE-2021-22146All versions of Elastic Cloud Enterprise has the Elasticsear…7.5
- CVE-2021-22147Elasticsearch before 7.14.0 did not apply document and field…6.5
- CVE-2021-22148Elastic Enterprise Search App Search versions before 7.14.0 …8.8
- CVE-2021-22149Elastic Enterprise Search App Search versions before 7.14.0 …8.8
Are you affected by CVE-2021-22143?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
