9.1
/ 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Description
Improper neutralization of special elements used in a template engine in Elastic Cloud Enterprise (ECE) can lead to a malicious actor with Admin access exfiltrating sensitive information and issuing commands via a specially crafted string where Jinjava variables are evaluated.
AI Analysis
AI processing failed - returned non-JSON response
Basic Information
ID
CVE-2025-37729
Source
elastic
Published
Oct 13, 2025 at 13:47
Affected Product
Vendor
Elastic
Product
Elastic Cloud Enterprise (ECE)
Version
2.5.0
Affected Versions
Elastic Elastic Cloud Enterprise (ECE) 2.5.0
Elastic Elastic Cloud Enterprise (ECE) 4.0.0
Elastic Elastic Cloud Enterprise (ECE) 4.0.0