Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-f6cj-4h3g-hwq4: APM Server vulnerable to Insertion of Sensitive Information into Log File

APM server logs contain document body from a partially failed bulk index request. For example, in case of unavailable_shards_exception for a specific document, since the ES response line contains the document body, and that APM server logs the ES response line on error, the document is effectively logged.

ghsa
#git

APM Server vulnerable to Insertion of Sensitive Information into Log File

Moderate severity GitHub Reviewed Published Aug 3, 2024 to the GitHub Advisory Database • Updated Aug 5, 2024

ghsa: Latest News

GHSA-7p9f-6x8j-gxxp: CRI-O: Maliciously structured checkpoint file can gain arbitrary node access