CVE-2024-37286

MEDIUM

Elastic Apm Server < 8.14.0 - Log Information Exposure

Title source: rule
STIX 2.1

Description

APM server logs contain document body from a partially failed bulk index request. For example, in case of unavailable_shards_exception for a specific document, since the ES response line contains the document body, and that APM server logs the ES response line on error, the document is effectively logged.

Scores

CVSS v3 5.7
EPSS 0.0043
EPSS Percentile 62.9%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-532
Status published
Products (2)
elastic/apm-server 0 - 8.14.0Go
elastic/apm_server < 8.14.0
Published Aug 03, 2024
Tracked Since Feb 18, 2026