APM Java Agent Local Privilege Escalation issue
High severity
GitHub Reviewed
Published
Nov 22, 2023
to the GitHub Advisory Database
•
Updated Nov 22, 2023
Package
Affected versions
>= 1.18.0, < 1.27.1
Patched versions
1.27.1
Description
Published by the National Vulnerability Database
Nov 22, 2023
Published to the GitHub Advisory Database
Nov 22, 2023
Reviewed
Nov 22, 2023
Last updated
Nov 22, 2023
A local privilege escalation issue was found with the APM Java agent, where a user on the system could attach a malicious plugin to an application running the APM Java agent. By using this vulnerability, an attacker could execute code at a potentially higher level of permissions than their user typically has access to.
References