Insertion of sensitive information in log file in Elasticsearch can lead to loss of confidentiality under specific preconditions when auditing requests to the reindex API https://www.elastic.co/docs/api/doc/elasticsearch/operation/operation-reindex
History

Fri, 10 Oct 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 10 Oct 2025 10:00:00 +0000

Type Values Removed Values Added
Description Insertion of sensitive information in log file in Elasticsearch can lead to loss of confidentiality under specific preconditions when auditing requests to the reindex API https://www.elastic.co/docs/api/doc/elasticsearch/operation/operation-reindex
Title Elasticsearch Insertion of sensitive information in log file
Weaknesses CWE-532
References
Metrics cvssV3_1

{'score': 5.7, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: elastic

Published: 2025-10-10T09:56:15.234Z

Updated: 2025-10-10T16:34:36.812Z

Reserved: 2025-04-16T03:24:04.510Z

Link: CVE-2025-37727

cve-icon Vulnrichment

Updated: 2025-10-10T16:34:32.919Z

cve-icon NVD

Status : Received

Published: 2025-10-10T10:15:34.167

Modified: 2025-10-10T10:15:34.167

Link: CVE-2025-37727

cve-icon Redhat

No data.