漏洞描述 Elastic APM是荷兰Elastic公司的用于监控和分析应用程序性能的平台。 Elastic APM Server 8.12.1之前版本存在日志信息泄露漏洞,该漏洞源于可能会导致在日志中插入敏感或私人信息。
相关漏洞推荐 Elastic Cloud Enterprise 访问控制不当漏洞 可导致权限提升 POC CVE-2014-3120: ElasticSearch v1.1.1/1.2 RCE POC CVE-2015-1427: ElasticSearch - Remote Code Execution POC CVE-2015-3337: Elasticsearch - Local File Inclusion POC CVE-2015-5531: ElasticSearch <1.6.1 - Local File Inclusion POC CVE-2021-22145: Elasticsearch 7.10.0-7.13.3 - Information Disclosure POC CVE-2022-22733: Apache ShardingSphere ElasticJob-UI privilege escalation POC CVE-2014-3120: ElasticSearch v1.1.1/1.2 RCE POC CVE-2015-1427: ElasticSearch - Remote Code Execution POC CVE-2015-3337: Elasticsearch File Read POC CVE-2015-5531: Elasticsearch CVE-2015-5531 POC CVE-2021-22145: ElasticSearch 7.13.3 - Memory disclosure POC elasticsearch-unauth: ElasticSearch Information Disclosure