Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:40488
HistoryMay 12, 2023 - 9:24 a.m.

Information Disclosure

2023-05-1209:24:38
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
10
github
elastic
beats
information
disclosure
vulnerability
http
request
authorization
proxy
header
logs
debug
logging
sensitive

0.0004 Low

EPSS

Percentile

9.0%

github.com/elastic/beats is vulnerable to Information Disclosure. A local authenticated attacker is able to gain access to http request authorization or proxy-authorization header contents through leaked logs due to a flaw in httpjson input when debug logging is enabled, resulting in disclosure of sensitive information.

0.0004 Low

EPSS

Percentile

9.0%

Related for VERACODE:40488