PT-2025-41008 · Cubepm · Cubepm

Prassan10

·

Published

2025-10-07

·

Updated

2025-10-07

·

CVE-2025-57564

CVSS v3.1

8.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions CubeAPM version nightly-2025-08-01-1
Description The software allows unauthenticated attackers to inject arbitrary log entries into production systems. This is possible through the /api/logs/insert/elasticsearch/ bulk API endpoint, which accepts bulk log data without authentication or input validation. Successful exploitation may result in false log entries, log poisoning, alert obfuscation, and potential performance degradation of the observability pipeline. The issue affects the core platform and is not limited to specific deployment configurations.
Recommendations Apply authentication to the /api/logs/insert/elasticsearch/ bulk API endpoint. Implement input validation for data received by the /api/logs/insert/elasticsearch/ bulk API endpoint.

Exploit

Fix

Weakness Enumeration

Related Identifiers

CVE-2025-57564

Affected Products

Cubepm