Github.Com Elastic Apm-Server vulnerabilities
2 known vulnerabilities affecting github.com/elastic_apm-server.
Total CVEs
2
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH1MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2024-37286MEDIUM≥ 0, < 8.14.02024-08-03
CVE-2024-37286 [MEDIUM] CWE-532 APM Server vulnerable to Insertion of Sensitive Information into Log File
APM Server vulnerable to Insertion of Sensitive Information into Log File
APM server logs contain document body from a partially failed bulk index request. For example, in case of unavailable_shards_exception for a specific document, since the ES response line contains the document body, and that APM server logs the ES response line on error, the document is effectively logged.
ghsaosv
CVE-2024-23448HIGH≥ 0, < 8.12.12024-02-08
CVE-2024-23448 [HIGH] CWE-532 APM Server vulnerable to Insertion of Sensitive Information into Log File
APM Server vulnerable to Insertion of Sensitive Information into Log File
An issue was discovered whereby APM Server could log at ERROR level, a response from Elasticsearch indicating that indexing the document failed and that response would contain parts of the original document. Depending on the nature of the document that the APM Server attempted to ingest, this could lead to the insertion
ghsaosv