Document Disclosure Vulnerability in APM Server by Elastic
CVE-2024-11994
What is CVE-2024-11994?
A vulnerability in APM Server allows for the unintended exposure of sensitive information due to improperly handled bulk index requests. When these requests partially fail, fragments of the document body may be logged, potentially leading to the disclosure of confidential user data in the error logs. This occurrence poses a significant risk to organizations relying on APM for monitoring and debugging, as sensitive information could be accessed by unauthorized users. It is crucial for users of affected APM Server versions to apply security updates to mitigate the risk of information leakage.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
APM Server 8.0.0 < 8.16.1
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved