GHSA-qqc5-rgcc-cjqh

Suggest an improvement
Source
https://github.com/advisories/GHSA-qqc5-rgcc-cjqh
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/05/GHSA-qqc5-rgcc-cjqh/GHSA-qqc5-rgcc-cjqh.json
JSON Data
https://api.test.osv.dev/v1/vulns/GHSA-qqc5-rgcc-cjqh
Aliases
Published
2021-05-18T18:34:18Z
Modified
2023-11-01T04:54:24.732432Z
Severity
  • 2.4 (Low) CVSS_V3 - CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N CVSS Calculator
Summary
Information Disclosure in go.elastic.co/apm
Details

The Elastic APM agent for Go versions before 1.11.0 can leak sensitive HTTP header information when logging the details during an application panic. Normally, the APM agent will sanitize sensitive HTTP header details before sending the information to the APM server. During an application panic it is possible the headers will not be sanitized before being sent.

Database specific
{
    "nvd_published_at": null,
    "github_reviewed": true,
    "github_reviewed_at": "2021-05-07T22:01:55Z",
    "severity": "LOW",
    "cwe_ids": [
        "CWE-532"
    ]
}
References

Affected packages

Go / go.elastic.co/apm

Package

Name
go.elastic.co/apm
View open source insights on deps.dev
Purl
pkg:golang/go.elastic.co/apm

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.11.0