Description
A local privilege escalation issue was found with the APM Java agent, where a user on the system could attach a malicious plugin to an application running the APM Java agent. By using this vulnerability, an attacker could execute code at a potentially higher level of permissions than their user typically has access to.
Remediation
References
https://discuss.elastic.co/t/apm-java-agent-security-update/291355
https://www.elastic.co/community/security
Related Vulnerabilities
CVE-2023-40014 Vulnerability in npm package @openzeppelin/contracts
CVE-2022-43430 Vulnerability in maven package com.compuware.jenkins:compuware-topaz-for-total-test
CVE-2017-17068 Vulnerability in npm package auth0-js
CVE-2023-26477 Vulnerability in maven package org.xwiki.platform:xwiki-platform-flamingo-theme-ui
CVE-2018-15494 Vulnerability in maven package org.webjars.bowergithub.dojo:dojox