CVE-2024-37283

An issue was discovered whereby Elastic Agent will leak secrets from the agent policy elastic-agent.yml only when the log level is configured to debug. By default the log level is set to info, where no leak occurs.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:elastic:elastic_agent:*:*:*:*:*:*:*:*

History

29 Sep 2025, 14:06

Type Values Removed Values Added
First Time Elastic elastic Agent
Elastic
CPE cpe:2.3:a:elastic:elastic_agent:*:*:*:*:*:*:*:*
Summary
  • (es) Se descubrió un problema por el cual Elastic Agent filtrará secretos de la política del agente elastic-agent.yml solo cuando el nivel de registro esté configurado para depurar. De forma predeterminada, el nivel de registro está configurado en información, donde no se produce ninguna fuga.
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5
References () https://discuss.elastic.co/t/elastic-agent-8-15-0-security-update-esa-2024-23/364635 - () https://discuss.elastic.co/t/elastic-agent-8-15-0-security-update-esa-2024-23/364635 - Patch, Issue Tracking, Vendor Advisory

12 Aug 2024, 13:41

Type Values Removed Values Added
New CVE

Information

Published : 2024-08-12 13:38

Updated : 2025-09-29 14:06


NVD link : CVE-2024-37283

Mitre link : CVE-2024-37283

CVE.ORG link : CVE-2024-37283


JSON object : View

Products Affected

elastic

  • elastic_agent
CWE
CWE-532

Insertion of Sensitive Information into Log File