GHSA-22jh-6gx8-f944
Dashboard / Vulnerabilities / GHSA-22jh-6gx8-f944
GHSA-22jh-6gx8-f944
Summary: Elastic APM agent for Python client CGI proxy redirection flaw
Details: When the Elastic APM agent for Python versions before 5.1.0 is run as a CGI script, there is a variable name clash flaw if a remote attacker can control the proxy header. This could result in an attacker redirecting collected APM data to a proxy of their choosing.
References: https://nvd.nist.gov/vuln/detail/CVE-2019-7617, https://discuss.elastic.co/t/elastic-apm-agent-for-python-5-1-0-security-update/196145, https://github.com/elastic/apm-agent-python, https://github.com/pypa/advisory-database/tree/main/vulns/elastic-apm/PYSEC-2019-178.yaml, https://www.elastic.co/community/security
Affected packages
Package
Name: elastic-apm
Purl: pkg:pypi/elastic-apm
Affected ranges
Type: ECOSYSTEM
Events:
