CVE-2025-37727
10.10.2025, 10:15
Insertion of sensitive information in log file in Elasticsearch can lead to loss of confidentiality under specific preconditions when auditing requests to the reindex API https://www.elastic.co/docs/api/doc/elasticsearch/operation/operation-reindexEnginsight
| Vendor | Product | Version |
|---|---|---|
| elastic | elasticsearch | 7.0.0 ≤ 𝑥 ≤ 7.17.29 |
| elastic | elasticsearch | 8.0.0 ≤ 𝑥 < 8.18.8 |
| elastic | elasticsearch | 8.19.0 ≤ 𝑥 < 8.19.5 |
| elastic | elasticsearch | 9.0.0 ≤ 𝑥 < 9.0.8 |
| elastic | elasticsearch | 9.1.0 ≤ 𝑥 < 9.1.5 |
𝑥
= Vulnerable software versions
Ubuntu Releases
Common Weakness Enumeration