APM Server Logs Vulnerable to Sensitive Information Injection
CVE-2024-23448

7.5HIGH

Key Information:

Vendor
Elastic
Vendor
CVE Published:
7 February 2024

Summary

A security vulnerability exists in Elastic's APM Server that allows sensitive information to be captured in server logs. When an attempt to index a document fails in Elasticsearch, the APM Server logs the error response at an ERROR level, which may inadvertently include portions of the original document. This creates a potential risk of exposing private data through log files, especially if the documents being ingested contain sensitive information. Proper logging practices and sanitization of logs are recommended to mitigate risks associated with this issue.

Affected Version(s)

APM Server 8.12 < 8.12.1

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.