CVE Database
/

CVE-2021-22133

Back to search

CVE-2021-22133

Published: Feb 10, 2021

Modified: Aug 3, 2024

PUBLISHED

Description

The Elastic APM agent for Go versions before 1.11.0 can leak sensitive HTTP header information when logging the details during an application panic. Normally, the APM agent will sanitize sensitive HTTP header details before sending the information to the APM server. During an application panic it is possible the headers will not be sanitized before being sent.

VendorProductVersions

Elastic

Elastic APM Agent for Go

affected
before 1.11.0

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now