CVE-2025-37727

Updated on 10 Oct 2025

Severity

5.7 Medium severity

Details

CVSS score
5.7
CVSS vector
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Overview

About vulnerability

Insertion of sensitive information in log file in Elasticsearch can lead to loss of confidentiality under specific preconditions when auditing requests to the reindex API https://www.elastic.co/docs/api/doc/elasticsearch/operation/operation-reindex

Details

Affected product:
Elasticsearch , Spring , elasticsearch , wildfly
Affected packages:
elasticsearch-rest-high-level-client @ 7.17.15 (+1038 more)
Insertion of sensitive information in log file in Elasticsearch can lead to loss of confidentiality under specific preconditions when auditing requests to the reindex API https://www.elastic.co/docs/api/doc/elasticsearch/operation/operation-reindex