HomeElasticCVE-2023-49921

CVE-2023-49921

MEDIUM
5.2CVSS
Published: 2024-07-26
Updated: 2024-11-21
AI Analysis

Description

An issue was discovered by Elastic whereby Watcher search input logged the search query results on DEBUG log level. This could lead to raw contents of documents stored in Elasticsearch to be printed in logs. Elastic has released 8.11.2 and 7.17.16 that resolves this issue by removing this excessive logging. This issue only affects users that use Watcher and have a Watch defined that uses the search input and additionally have set the search input’s logger to DEBUG or finer, for example using: org.elasticsearch.xpack.watcher.input.search, org.elasticsearch.xpack.watcher.input, org.elasticsearch.xpack.watcher, or wider, since the loggers are hierarchical.

CVSS Metrics

Vector
CVSS:3.1/AV:A/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N
Attack Vector
adjacent network
Complexity
low
Privileges
low
User Action
required
Scope
unchanged
Confidentiality
high
Integrity
none
Availability
none
Weaknesses
CWE-532CWE-532

Metadata

Primary Vendor
ELASTIC
Published
7/26/2024
Last Modified
11/21/2024
Source
NIST NVD
Note: Verify all details with official vendor sources before applying patches.

Affected Products

elastic : elasticsearchelastic : elasticsearch

AI-Powered Remediation

Generate remediation guidance or a C-suite brief for this vulnerability.

Executive Intelligence Brief

CVE-CVE-2023-49921 | MEDIUM Severity | CVEDatabase.com | CVEDatabase.com