{"id":"GHSA-5xqm-hc45-f2g2","summary":"APM Java Agent Local Privilege Escalation issue","details":"A local privilege escalation issue was found with the APM Java agent, where a user on the system could attach a malicious plugin to an application running the APM Java agent. By using this vulnerability, an attacker could execute code at a potentially higher level of permissions than their user typically has access to.","aliases":["CVE-2021-37942"],"modified":"2025-09-30T17:23:17.050609Z","published":"2023-11-22T03:30:19Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2023-11-22T20:57:05Z","nvd_published_at":"2023-11-22T02:15:42Z","cwe_ids":["CWE-269"],"severity":"HIGH"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2021-37942"},{"type":"WEB","url":"https://discuss.elastic.co/t/apm-java-agent-security-update/291355"},{"type":"PACKAGE","url":"https://github.com/elastic/apm-agent-java"},{"type":"WEB","url":"https://www.elastic.co/community/security"}],"affected":[{"package":{"name":"co.elastic.apm:apm-agent-parent","ecosystem":"Maven","purl":"pkg:maven/co.elastic.apm/apm-agent-parent"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"1.18.0"},{"fixed":"1.27.1"}]}],"versions":["1.18.0","1.18.1","1.19.0","1.20.0","1.21.0","1.22.0","1.23.0","1.24.0","1.25.0","1.26.0","1.26.1","1.26.2","1.27.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/11/GHSA-5xqm-hc45-f2g2/GHSA-5xqm-hc45-f2g2.json"}},{"package":{"name":"co.elastic.apm:elastic-apm-agent","ecosystem":"Maven","purl":"pkg:maven/co.elastic.apm/elastic-apm-agent"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"1.18.0"},{"fixed":"1.27.1"}]}],"versions":["1.18.0","1.18.1","1.19.0","1.20.0","1.21.0","1.22.0","1.23.0","1.24.0","1.25.0","1.26.0","1.26.1","1.26.2","1.27.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/11/GHSA-5xqm-hc45-f2g2/GHSA-5xqm-hc45-f2g2.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}