Low severity2.1NVD Advisory· Published Nov 22, 2023· Updated Jun 17, 2026
CVE-2021-22143
CVE-2021-22143
Description
The Elastic APM .NET Agent can leak sensitive HTTP header information when logging the details during an application error. Normally, the APM agent will sanitize sensitive HTTP header details before sending the information to the APM server. During an application error it is possible the headers will not be sanitized before being sent.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
Elastic.ApmNuGet | < 1.10.0 | 1.10.0 |
Affected products
2Patches
Vulnerability mechanics
References
6- discuss.elastic.co/t/elastic-apm-net-agent-1-10-0-security-update/274668nvdVendor AdvisoryWEB
- github.com/advisories/GHSA-hx93-gc73-5rprghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2021-22143ghsaADVISORY
- www.elastic.co/community/securitynvdVendor AdvisoryWEB
- github.com/elastic/apm-agent-dotnet/commit/c2b519aaa0fe5e5044b736cfec695342f124bf30ghsaWEB
- github.com/elastic/apm-agent-dotnet/pull/1286ghsaWEB
News mentions
0No linked articles in our index yet.