CVE-2025-37727

Updated on 10 Oct 2025

Severity

5.7 Medium severity

Details

CVSS score
5.7
CVSS vector
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Overview

About vulnerability

Insertion of sensitive information in log file in Elasticsearch can lead to loss of confidentiality under specific preconditions when auditing requests to the reindex API https://www.elastic.co/docs/api/doc/elasticsearch/operation/operation-reindex

Details

Affected product:
Elasticsearch , Spring , Wildfly , elasticsearch , wildfly
Affected packages:
elasticsearch-x-content @ 7.17.15 (+2035 more)
Insertion of sensitive information in log file in Elasticsearch can lead to loss of confidentiality under specific preconditions when auditing requests to the reindex API https://www.elastic.co/docs/api/doc/elasticsearch/operation/operation-reindex