Home
MEDIUM: 5.7 CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NDefault status
unaffected
7.0.0 (semver)
affected
8.0.0 (semver)
affected
8.19.0 (semver)
affected
9.0.0 (semver)
affected
9.1.0 (semver)
affected
Description
Insertion of sensitive information in log file in Elasticsearch can lead to loss of confidentiality under specific preconditions when auditing requests to the reindex API https://www.elastic.co/docs/api/doc/elasticsearch/operation/operation-reindex
Problem types
CWE-532 Insertion of Sensitive Information into Log File
Product status
7.0.0 (semver)
8.0.0 (semver)
8.19.0 (semver)
9.0.0 (semver)
9.1.0 (semver)
References
discuss.elastic.co/...1-5-security-update-esa-2025-18/382453