QID 982557
QID 982557: Go (go) Security Update for go.elastic.co/apm (GHSA-qqc5-rgcc-cjqh)
The Elastic APM agent for Go versions before 1.11.0 can leak sensitive HTTP header information when logging the details during an application panic. Normally, the APM agent will sanitize sensitive HTTP header details before sending the information to the APM server. During an application panic it is possible the headers will not be sanitized before being sent.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-qqc5-rgcc-cjqh for updates pertaining to this vulnerability.
Vendor References
- GHSA-qqc5-rgcc-cjqh -
github.com/advisories/GHSA-qqc5-rgcc-cjqh
CVEs related to QID 982557
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-qqc5-rgcc-cjqh | go.elastic.co/apm |
|