{"id":"CVE-2024-37286","summary":"APM Server Insertion of Sensitive Information into Log File","details":"APM server logs contain document body from a partially failed bulk index request. For example, in case of unavailable_shards_exception for a specific document, since the ES response line contains the document body, and that APM server logs the ES response line on error, the document is effectively logged.","aliases":["GHSA-f6cj-4h3g-hwq4","GO-2024-3037"],"modified":"2026-08-12T03:51:18.618932204Z","published":"2024-08-03T15:16:22.700Z","database_specific":{"cna_assigner":"elastic","cwe_ids":["CWE-532"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/37xxx/CVE-2024-37286.json"},"references":[{"type":"WEB","url":"https://discuss.elastic.co/t/apm-server-8-14-0-security-update-esa-2024-19/364289"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/37xxx/CVE-2024-37286.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-37286"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/elastic/apm-server","events":[{"introduced":"0"},{"fixed":"a440663cd3f924b3de4453a4c9737a9c72157ee3"}],"database_specific":{"source":"CPE_RANGE","cpe":"cpe:2.3:a:elastic:apm_server:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"8.14.0"}]}}],"versions":["v8.0.0-alpha2","v8.0.0-alpha1","v7.0.0-alpha2","v7.0.0-alpha1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-37286.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"}]}