github.com/elastic/apm-server vulnerabilities
CVEs whose affected-version data names the github.com/elastic/apm-server package (go). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2024-37286Medium· 5.7APM Server vulnerable to Insertion of Sensitive Information into Log File
APM Server vulnerable to Insertion of Sensitive Information into Log File
▾ Sunlitelastic · github.com/elastic/apm-serverEPSS 0.49%via OSV
CVE-2024-23448Medium· 5.7APM Server vulnerable to Insertion of Sensitive Information into Log File
APM Server vulnerable to Insertion of Sensitive Information into Log File
▾ Sunlitelastic · github.com/elastic/apm-serverEPSS 0.67%via OSV