Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-49923


An issue was discovered by Elastic whereby the Documents API of App Search logged the raw contents of indexed documents at INFO log level. Depending on the contents of such documents, this could lead to the insertion of sensitive or private information in the App Search logs. Elastic has released 8.11.2 and 7.17.16 that resolves this issue by changing the log level at which these are logged to DEBUG, which is disabled by default.


Published

2023-12-12T18:15:23.153

Last Modified

2024-11-21T08:34:00.793

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 6.8 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-532
  • Type: Primary
    CWE-532

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application elastic enterprise_search < 7.17.16 Yes
Application elastic enterprise_search < 8.11.2 Yes

References