{"id":"CVE-2021-37942","details":"A local privilege escalation issue was found with the APM Java agent, where a user on the system could attach a malicious plugin to an application running the APM Java agent. By using this vulnerability, an attacker could execute code at a potentially higher level of permissions than their user typically has access to.","aliases":["GHSA-5xqm-hc45-f2g2"],"modified":"2026-07-08T23:46:27.251467Z","published":"2023-11-22T02:15:42.220Z","references":[{"type":"WEB","url":"https://www.elastic.co/community/security"},{"type":"ADVISORY","url":"https://discuss.elastic.co/t/apm-java-agent-security-update/291355"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/elastic/apm-agent-java","events":[{"introduced":"11313a510b8783147a100306efc1e915ef8d9ff1"},{"last_affected":"eba15c19a61de14ffb104343c4e836e7a0f15f0d"}],"database_specific":{"cpe":"cpe:2.3:a:elastic:apm_java_agent:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"1.18.0"},{"last_affected":"1.27.0"}],"source":"CPE_RANGE"}}],"versions":["v1.27.0","v1.26.0","v1.25.0","v1.24.0","v1.23.0","stable","v1.22.0","v1.21.0","v1.20.0","v1.19.0","v1.18.1","v1.18.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-37942.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}