APM Server Logs Vulnerable to Sensitive Information Injection
CVE-2024-23448
7.5HIGH
What is CVE-2024-23448?
A security vulnerability exists in Elastic's APM Server that allows sensitive information to be captured in server logs. When an attempt to index a document fails in Elasticsearch, the APM Server logs the error response at an ERROR level, which may inadvertently include portions of the original document. This creates a potential risk of exposing private data through log files, especially if the documents being ingested contain sensitive information. Proper logging practices and sanitization of logs are recommended to mitigate risks associated with this issue.
Affected Version(s)
APM Server 8.12 < 8.12.1