PT-2025-41309 · Elastic · Elasticsearch

Ismisepaul

+1

·

Published

2025-10-08

·

Updated

2026-04-28

·

CVE-2025-37727

CVSS v3.1

5.7

Medium

VectorAV:A/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Elasticsearch versions 8.18.8, 8.19.5, 9.0.8, and 9.1.5
Description A flaw exists in Elasticsearch where the insertion of sensitive information into log files can result in a loss of confidentiality under certain conditions. This occurs specifically when auditing requests to the reindex API.
Recommendations Update to Elasticsearch version 8.18.9 or later. Update to Elasticsearch version 8.19.6 or later. Update to Elasticsearch version 9.0.9 or later. Update to Elasticsearch version 9.1.6 or later.

Fix

Insertion into Log File

Weakness Enumeration

Related Identifiers

BIT-ELASTICSEARCH-2025-37727
CVE-2025-37727
ECHO-5478-882B-E488
GHSA-56R7-H6MW-RCFV

Affected Products

Elasticsearch