PT-2024-27448 · Elastic · Apm Server

Published

2024-08-03

·

Updated

2024-09-11

·

CVE-2024-37286

CVSS v4.0

6.9

Medium

VectorAV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Elastic APM Server versions prior to 8.14.0
Description The issue concerns the logging of sensitive data by the APM server due to a flaw related to unavailable shards exception. When a bulk index request partially fails, the APM server logs the Elasticsearch response line, which contains the document body, thus effectively logging sensitive information. This can lead to information exposure.
Recommendations For Elastic APM Server versions prior to 8.14.0, upgrade to version 8.14.0 or later to mitigate the risk of sensitive data exposure. As a temporary workaround, consider restricting the logging of Elasticsearch response lines on error to minimize the risk of sensitive information being logged.

Fix

Insertion into Log File

Weakness Enumeration

Related Identifiers

CVE-2024-37286
GHSA-F6CJ-4H3G-HWQ4
GO-2024-3037

Affected Products

Apm Server