CVE-2025-37729: Elastic Cloud Enterprise (ECE) Improper Neutralization of Special Elements Used in a Template Engine
Improper neutralization of special elements used in a template engine in Elastic Cloud Enterprise (ECE) can lead to a malicious actor with Admin access exfiltrating sensitive information and issuing commands via a specially crafted string where Jinjava variables are evaluated.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-37729?
CVE-2025-37729 is classified as a high severity vulnerability due to its potential for sensitive information exfiltration.
How do I fix CVE-2025-37729?
To remediate CVE-2025-37729, update Elastic Cloud Enterprise to the latest version that addresses this vulnerability.
Who is affected by CVE-2025-37729?
CVE-2025-37729 affects users of Elastic Cloud Enterprise with Admin access.
What type of vulnerability is CVE-2025-37729?
CVE-2025-37729 is an improper neutralization vulnerability in a template engine used by Elastic Cloud Enterprise.
What can an attacker do with CVE-2025-37729?
An attacker with Admin access can exploit CVE-2025-37729 to exfiltrate sensitive information and execute unauthorized commands.