An issue was identified in Fleet Server where Fleet policies that could contain sensitive information were logged on INFO and ERROR log levels. The nature of the sensitive information largely depends on the integrations enabled.
Metrics
Affected Vendors & Products
References
History
Thu, 23 Jan 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 23 Jan 2025 07:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An issue was identified in Fleet Server where Fleet policies that could contain sensitive information were logged on INFO and ERROR log levels. The nature of the sensitive information largely depends on the integrations enabled. | |
| Title | Fleet Server sensitive information exposure via logs | |
| Weaknesses | CWE-200 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: elastic
Published: 2025-01-23T07:19:39.170Z
Updated: 2025-01-23T14:45:48.260Z
Reserved: 2024-11-18T14:48:22.150Z
Link: CVE-2024-52975
Updated: 2025-01-23T14:45:42.245Z
Status : Received
Published: 2025-01-23T08:15:16.990
Modified: 2025-01-23T08:15:16.990
Link: CVE-2024-52975
No data.