Description
An issue was discovered whereby APM Server could log at ERROR level, a response from Elasticsearch indicating that indexing the document failed and that response would contain parts of the original document. Depending on the nature of the document that the APM Server attempted to ingest, this could lead to the insertion of sensitive or private information in the APM Server logs.
Published: 2024-02-07
Score: 5.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2024-0582 An issue was discovered whereby APM Server could log at ERROR level, a response from Elasticsearch indicating that indexing the document failed and that response would contain parts of the original document. Depending on the nature of the document that the APM Server attempted to ingest, this could lead to the insertion of sensitive or private information in the APM Server logs.
Github GHSA Github GHSA GHSA-8r33-q5j5-rh7g APM Server vulnerable to Insertion of Sensitive Information into Log File
History

No history.

Subscriptions

Elastic Apm Server
cve-icon MITRE

Status: PUBLISHED

Assigner: elastic

Published:

Updated: 2024-08-01T23:06:24.582Z

Reserved: 2024-01-16T21:31:26.030Z

Link: CVE-2024-23448

cve-icon Vulnrichment

Updated: 2024-08-01T23:06:24.582Z

cve-icon NVD

Status : Modified

Published: 2024-02-07T22:15:09.987

Modified: 2024-11-21T08:57:43.770

Link: CVE-2024-23448

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses