CVE-2025-37727: Elasticsearch Insertion of sensitive information in log file
Elasticsearch Insertion of sensitive information in log file
Other sources
Insertion of sensitive information in log file in Elasticsearch can lead to loss of confidentiality under specific preconditions when auditing requests to the reindex API https://www.elastic.co/docs/api/doc/elasticsearch/operation/operation-reindex
— GitHub
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-37727?
CVE-2025-37727 has a high severity rating due to the potential loss of confidentiality.
How do I fix CVE-2025-37727?
To fix CVE-2025-37727, update your Elasticsearch instance to the latest version provided in the security update.
What kind of information is affected by CVE-2025-37727?
CVE-2025-37727 affects the sensitive information logged during auditing requests to the reindex API.
In which versions is CVE-2025-37727 found?
CVE-2025-37727 is found in specific versions of Elasticsearch that are vulnerable to this logging issue.
What are the implications of CVE-2025-37727?
The implications of CVE-2025-37727 include potential exposure of sensitive data, leading to security breaches.