Feed/CVE-2025-37727
CVE-2025-37727MEDIUMCVSS 5.7

CVE-2025-37727

Published Oct 10, 2025·Updated Sep 29, 2026

NVD Description

Insertion of sensitive information in log file in Elasticsearch can lead to loss of confidentiality under specific preconditions when auditing requests to the reindex API https://www.elastic.co/docs/api/doc/elasticsearch/operation/operation-reindex

Affected Packages (1)

org.elasticsearch.plugin:reindex-clientMAVEN
From 7.0.0
Fixed in 8.18.8

CVSS Vector

CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free