Safety vulnerability ID: 62643
The information on this page was manually curated by our Cybersecurity Intelligence Team.
A local privilege escalation vulnerability was identified in the APM Java agent, potentially also affecting the elastic-apm Python module, which shares identical release version numbers. This vulnerability allows a system user to attach a malicious file to an application monitored by the APM agent, thereby enabling them to execute commands at a higher permission level than their own. It specifically impacts configurations using the attacher CLI (version 3), the attach API (version 2), or those with the 'profiling_inferred_spans_enabled' option active.
Latest version: 6.23.0
The official Python module for Elastic APM
This vulnerability has no description
Scan your Python project for dependency vulnerabilities in two minutes
Scan your application