Insertion of sensitive information in log file in Elasticsearch can lead to loss of confidentiality under specific preconditions when auditing requests to the reindex API https://www.elastic.co/docs/api/doc/elasticsearch/operation/operation-reindex
History

Wed, 22 Oct 2025 00:15:00 +0000


Mon, 20 Oct 2025 16:30:00 +0000

Type Values Removed Values Added
First Time appeared Elastic
Elastic elasticsearch
Vendors & Products Elastic
Elastic elasticsearch

Fri, 10 Oct 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 10 Oct 2025 10:00:00 +0000

Type Values Removed Values Added
Description Insertion of sensitive information in log file in Elasticsearch can lead to loss of confidentiality under specific preconditions when auditing requests to the reindex API https://www.elastic.co/docs/api/doc/elasticsearch/operation/operation-reindex
Title Elasticsearch Insertion of sensitive information in log file
Weaknesses CWE-532
References
Metrics cvssV3_1

{'score': 5.7, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: elastic

Published: 2025-10-10T09:56:15.234Z

Updated: 2025-10-10T16:34:36.812Z

Reserved: 2025-04-16T03:24:04.510Z

Link: CVE-2025-37727

cve-icon Vulnrichment

Updated: 2025-10-10T16:34:32.919Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-10-10T10:15:34.167

Modified: 2025-10-14T19:37:28.107

Link: CVE-2025-37727

cve-icon Redhat

Severity : Moderate

Publid Date: 2025-10-10T09:56:15Z

Links: CVE-2025-37727 - Bugzilla