CVE-2024-37283

MEDIUM

Elastic Agent < 8.15.0 - Log Information Exposure

Title source: rule
STIX 2.1

Description

An issue was discovered whereby Elastic Agent will leak secrets from the agent policy elastic-agent.yml only when the log level is configured to debug. By default the log level is set to info, where no leak occurs.

Scores

CVSS v3 6.5
EPSS 0.0037
EPSS Percentile 59.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-532
Status published
Products (1)
elastic/elastic_agent 8.6.0 - 8.15.0
Published Aug 12, 2024
Tracked Since Feb 18, 2026