Description
When the Elastic APM agent for Python versions before 5.1.0 is run as a CGI script, there is a variable name clash flaw if a remote attacker can control the proxy header. This could result in an attacker redirecting collected APM data to a proxy of their choosing.
Published: 2019-08-22
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2019-0048 When the Elastic APM agent for Python versions before 5.1.0 is run as a CGI script, there is a variable name clash flaw if a remote attacker can control the proxy header. This could result in an attacker redirecting collected APM data to a proxy of their choosing.
Github GHSA Github GHSA GHSA-22jh-6gx8-f944 Elastic APM agent for Python client CGI proxy redirection flaw
History

No history.

Subscriptions

Elastic Apm Agent
cve-icon MITRE

Status: PUBLISHED

Assigner: elastic

Published:

Updated: 2024-08-04T20:54:28.320Z

Reserved: 2019-02-07T00:00:00.000Z

Link: CVE-2019-7617

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2019-08-22T17:15:10.357

Modified: 2024-11-21T04:48:24.660

Link: CVE-2019-7617

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses