CVE Vulnerabilities

CVE-2025-37727

Insertion of Sensitive Information into Log File

Published: Oct 10, 2025 | Modified: Dec 23, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
5.7 MODERATE
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Insertion of sensitive information in log file in Elasticsearch can lead to loss of confidentiality under specific preconditions when auditing requests to the reindex API https://www.elastic.co/docs/api/doc/elasticsearch/operation/operation-reindex

Weakness

The product writes sensitive information to a log file.

Affected Software

NameVendorStart VersionEnd Version
ElasticsearchElastic7.0.0 (including)7.17.29 (including)
ElasticsearchElastic8.0.0 (including)8.18.8 (excluding)
ElasticsearchElastic8.19.0 (including)8.19.5 (excluding)
ElasticsearchElastic9.0.0 (including)9.0.8 (excluding)
ElasticsearchElastic9.1.0 (including)9.1.5 (excluding)

Potential Mitigations

References