VDB

CVE-2023-49921

CVE-2023-49921 PUBLISHED

An issue was discovered by Elastic whereby Watcher search input logged the search query results on DEBUG log level. This could lead to raw contents of documents stored in Elasticsearch to be printed in logs. Elastic has released 8.11.2 and 7.17.16 that resolves this issue by removing this excessive logging. This issue only affects users that use Watcher and have a Watch defined that uses the search input and additionally have set the search input’s logger to DEBUG or finer, for example using: org.elasticsearch.xpack.watcher.input.search, org.elasticsearch.xpack.watcher.input, org.elasticsearch.xpack.watcher, or wider, since the loggers are hierarchical.

EPSS 0.70% · 72.4th percentile

Risk Scores

EPSS Score
0.70%
72.4th percentile

Affected Products

VendorProductVersions
Bitnamielasticsearch7.0.0, 8.0.0
Bitnamielasticsearch7.0.0, 8.0.0, 7.0.0

Exploit Intelligence

Timeline

  • Dec 12, 2023 CVE Published
  • Jul 26, 2024 EPSS Score
  • Aug 16, 2024 EPSS Score
  • Sep 7, 2024 EPSS Score
  • Sep 28, 2024 EPSS Score
  • Oct 20, 2024 EPSS Score
  • Nov 10, 2024 EPSS Score
  • Dec 3, 2024 EPSS Score
  • Dec 24, 2024 EPSS Score
  • Jan 15, 2025 EPSS Score
  • Feb 5, 2025 EPSS Score
  • Feb 26, 2025 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›