Overview
About vulnerability
Insertion of sensitive information in log file in Elasticsearch can lead to loss of confidentiality under specific preconditions when auditing requests to the reindex API https://www.elastic.co/docs/api/doc/elasticsearch/operation/operation-reindexDetails
- Affected product:
- Elasticsearch , Spring , elasticsearch , wildfly
- Affected packages:
- elasticsearch-rest-high-level-client @ 7.17.15 (+1038 more)