← back
CVE-2018-3827

CVE-2018-3827

EPSS 1.0%CWE-532
Vexday Risk Score
3Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS EPSS 1.0%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
19 Sep 2018Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
A sensitive data disclosure flaw was found in the Elasticsearch repository-azure (formerly elasticsearch-cloud-azure) plugin. When the repository-azure plugin is set to log at TRACE level Azure credentials can be inadvertently logged.
Affected products
Elastic · Elasticsearch

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →