PT-2025-41008 · Cubepm · Cubepm
Prassan10
·
Published
2025-10-07
·
Updated
2025-10-07
·
CVE-2025-57564
CVSS v3.1
8.2
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
CubeAPM version nightly-2025-08-01-1
Description
The software allows unauthenticated attackers to inject arbitrary log entries into production systems. This is possible through the
/api/logs/insert/elasticsearch/ bulk API endpoint, which accepts bulk log data without authentication or input validation. Successful exploitation may result in false log entries, log poisoning, alert obfuscation, and potential performance degradation of the observability pipeline. The issue affects the core platform and is not limited to specific deployment configurations.Recommendations
Apply authentication to the
/api/logs/insert/elasticsearch/ bulk API endpoint.
Implement input validation for data received by the /api/logs/insert/elasticsearch/ bulk API endpoint.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cubepm