PT-2024-27448 · Elastic · Apm Server

CVE-2024-37286

·

Published

2024-08-03

·

Updated

2024-09-11

CVSS v4.0

6.9

Medium

VectorAV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Elastic APM Server versions prior to 8.14.0
Description The issue concerns the logging of sensitive data by the APM server due to a flaw related to unavailable shards exception. When a bulk index request partially fails, the APM server logs the Elasticsearch response line, which contains the document body, thus effectively logging sensitive information. This can lead to information exposure.
Recommendations For Elastic APM Server versions prior to 8.14.0, upgrade to version 8.14.0 or later to mitigate the risk of sensitive data exposure. As a temporary workaround, consider restricting the logging of Elasticsearch response lines on error to minimize the risk of sensitive information being logged.

Exploit

Fix

Insertion into Log File

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-37286
GHSA-F6CJ-4H3G-HWQ4
GO-2024-3037

Affected Products

Apm Server