Home
MEDIUM: 5.7 CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NDefault status
unaffected
8.0.0 (semver) before 8.16.1
affected
Description
APM server logs could contain parts of the document body from a partially failed bulk index request. Depending on the nature of the document, this could disclose sensitive information in APM Server error logs.
Problem types
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
Product status
8.0.0 (semver) before 8.16.1
References
discuss.elastic.co/...6-1-security-update-esa-2024-41/377710