ZeroHour

CVE-2025-37727

CVSS 3.1
5.7 medium
EPSS
<1%p14
Published
()
Modified
Description

Insertion of sensitive information in log file in Elasticsearch can lead to loss of confidentiality under specific preconditions when auditing requests to the reindex API https://www.elastic.co/docs/api/doc/elasticsearch/operation/operation-reindex

Vendors
elastic
Products
elasticsearch
Weakness
CWE-532
Vector
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.