VDB
Sign up
—

PYSEC-2019-178

Quick fix

PYSEC-2019-178 — elastic-apm: upgrade to the fixed version with the command below.

pip install --upgrade 'elastic-apm>=5.1.0'

Details

When the Elastic APM agent for Python versions before 5.1.0 is run as a CGI script, there is a variable name clash flaw if a remote attacker can control the proxy header. This could result in an attacker redirecting collected APM data to a proxy of their choosing.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/elastic-apm
Introduced in: 0Fixed in: 5.1.0
Fixpip install --upgrade 'elastic-apm>=5.1.0'

References