5.7
/ 10
MEDIUM
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Description
Insertion of sensitive information in log file in Elasticsearch can lead to loss of confidentiality under specific preconditions when auditing requests to the reindex API https://www.elastic.co/docs/api/doc/elasticsearch/operation/operation-reindex
Basic Information
ID
CVE-2025-37727
Source
elastic
Published
Oct 10, 2025 at 09:56
Affected Product
Vendor
Elastic
Product
Elasticsearch
Version
7.0.0
Affected Versions
Elastic Elasticsearch 7.0.0
Elastic Elasticsearch 8.0.0
Elastic Elasticsearch 8.19.0
Elastic Elasticsearch 9.0.0
Elastic Elasticsearch 9.1.0
Elastic Elasticsearch 8.0.0
Elastic Elasticsearch 8.19.0
Elastic Elasticsearch 9.0.0
Elastic Elasticsearch 9.1.0