CVE-2024-23448 MEDIUM

CVE-2024-23448: APM Server Insertion of Sensitive Information into Log File

Vendor Elastic
Product APM Server
Weakness CWE-532 · Sensitive info in logs
Published February 7, 2024
Last update August 1, 2024

CVSS base score

5.7/10
Attack vector Adjacent
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality High
Integrity None

CVSS vector

CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

What the vulnerability does

01Description

An issue was discovered whereby APM Server could log at ERROR level, a response from Elasticsearch indicating that indexing the document failed and that response would contain parts of the original document. Depending on the nature of the document that the APM Server attempted to ingest, this could lead to the insertion of sensitive or private information in the APM Server logs.

Key dates

02Disclosure timeline

February 7, 2024 CVE published
August 1, 2024 Record updated