Improper restriction of environment variables in Elastic Defend can lead to exposure of sensitive information such as API keys and tokens via automatic transmission of unfiltered environment variables to the stack.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-14853 | Improper restriction of environment variables in Elastic Defend can lead to exposure of sensitive information such as API keys and tokens via automatic transmission of unfiltered environment variables to the stack. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 09 Apr 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 08 Apr 2025 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper restriction of environment variables in Elastic Defend can lead to exposure of sensitive information such as API keys and tokens via automatic transmission of unfiltered environment variables to the stack. | |
| Title | Elastic Defend Insertion of Sensitive Information into Log Files | |
| Weaknesses | CWE-532 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: elastic
Published:
Updated: 2025-04-09T19:28:32.185Z
Reserved: 2025-01-31T15:28:16.917Z
Link: CVE-2025-25013
Updated: 2025-04-09T19:28:10.773Z
Status : Awaiting Analysis
Published: 2025-04-08T23:15:45.540
Modified: 2025-04-09T20:02:41.860
Link: CVE-2025-25013
No data.
OpenCVE Enrichment
No data.
EUVD