Description
A local privilege escalation issue was found with the APM Java agent, where a user on the system could attach a malicious plugin to an application running the APM Java agent. By using this vulnerability, an attacker could execute code at a potentially higher level of permissions than their user typically has access to.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-2892 | APM Java Agent Local Privilege Escalation issue |
Github GHSA |
GHSA-5xqm-hc45-f2g2 | APM Java Agent Local Privilege Escalation issue |
References
History
No history.
Status: PUBLISHED
Assigner: elastic
Published:
Updated: 2024-08-04T01:30:09.172Z
Reserved: 2021-08-03T20:49:52.462Z
Link: CVE-2021-37942
No data.
Status : Modified
Published: 2023-11-22T02:15:42.220
Modified: 2024-11-21T06:16:07.267
Link: CVE-2021-37942
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA