Impact
The vulnerability is a CWE-532 defect where sensitive request headers are recorded in Kibana's application logs when the optional APM instrumentation is enabled. This unintended logging exposes those headers to anyone who has read access to the log files, thereby disclosing potentially confidential information.
Affected Systems
The issue affects Elastic Kibana instances that have APM instrumentation enabled. Any deployment in which this feature is active can write request header values to the standard application logs, allowing operator-level access to sensitive data. No specific version range is cited in the advisory, so multiple Kibana releases may be impacted.
Risk and Exploitability
The CVSS score of 4.4 places the vulnerability at moderate severity. The EPSS score of <1% indicates a very low probability of exploitation. It is inferred that an attacker would need to send crafted HTTP requests that set sensitive headers and also possess the ability to read the Kibana log files; therefore the risk is primarily to insiders or external actors who gain log-file access. The vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment