CVE-2024-37286

Severity CVSS v4.0:
Pending analysis
Type:
CWE-532 Information Exposure Through Log Files
Publication date:
03/08/2024
Last modified:
11/09/2024

Description

APM server logs contain document body from a partially failed bulk index request. For example, in case of unavailable_shards_exception for a specific document, since the ES response line contains the document body, and that APM server logs the ES response line on error, the document is effectively logged.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:elastic:apm_server:*:*:*:*:*:*:*:* 8.14.0 (excluding)