MEDIUM 5.7 Maven

Elasticsearch: Insertion of Sensitive Information into Log File via reindex API

GHSA-56r7-h6mw-rcfv · BIT-elasticsearch-2025-37727 · CVE-2025-37727

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

Insertion of sensitive information in log file in Elasticsearch can lead to loss of confidentiality under specific preconditions when auditing requests to the reindex API https://www.elastic.co/docs/api/doc/elasticsearch/operation/operation-reindex

Ready to move

Start Securing

Free, no credit card | First findings in minutes