PT-2023-31412 · Elastic · App Search
CVE-2023-49923
·
Publicado
2023-12-12
·
Atualizado
2023-12-19
CVSS v3.1
6.8
Média
| Vetor | AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Elastic App Search versions prior to 7.17.16
Elastic App Search versions prior to 8.11.2
Description
An issue was discovered in the Documents API of App Search where it logged the raw contents of indexed documents at INFO log level. This could lead to the insertion of sensitive or private information in the App Search logs, depending on the contents of such documents.
Recommendations
For versions prior to 7.17.16, update to version 7.17.16 to resolve the issue.
For versions prior to 8.11.2, update to version 8.11.2 to resolve the issue.
Correção
Insertion into Log File
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
App Search