First published: Thu Aug 08 2024(Updated: )
An issue was discovered whereby Elastic Agent will leak secrets from the agent policy elastic-agent.yml only when the log level is configured to debug. By default the log level is set to info, where no leak occurs.
Credit: bressers@elastic.co
Affected Software | Affected Version | How to fix |
---|---|---|
Elastic |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-37283 has a moderate severity level due to the potential leakage of sensitive secrets in debug logs.
To fix CVE-2024-37283, configure the Elastic Agent log level to 'info' instead of 'debug'.
CVE-2024-37283 affects the Elastic Agent when the log level is set to 'debug'.
If CVE-2024-37283 is not addressed, sensitive secrets may be exposed in the logs when the debug log level is enabled.
Yes, CVE-2024-37283 poses a risk for production environments if debug logging is left enabled.