CVE-2024-37286
MEDIUMElastic Apm Server < 8.14.0 - Log Information Exposure
Title source: ruleDescription
APM server logs contain document body from a partially failed bulk index request. For example, in case of unavailable_shards_exception for a specific document, since the ES response line contains the document body, and that APM server logs the ES response line on error, the document is effectively logged.
Scores
CVSS v3
5.7
EPSS
0.0043
EPSS Percentile
62.9%
Attack Vector
ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-532
Status
published
Products (2)
elastic/apm-server
0 - 8.14.0Go
elastic/apm_server
< 8.14.0
Published
Aug 03, 2024
Tracked Since
Feb 18, 2026