Lucene search

K
cvelistElasticCVELIST:CVE-2023-31413
HistoryMay 04, 2023 - 12:00 a.m.

CVE-2023-31413

2023-05-0400:00:00
CWE-200
elastic
www.cve.org
2
filebeat
httpjson
authorization headers
logs
debugging

4.2 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

9.0%

Filebeat versions through 7.17.9 and 8.6.2 have a flaw in httpjson input that allows the http request Authorization or Proxy-Authorization header contents to be leaked in the logs when debug logging is enabled.

CNA Affected

[
  {
    "vendor": "Elastic",
    "product": "Filebeat",
    "versions": [
      {
        "version": "versions through 7.17.9 and 8.6.2",
        "status": "affected"
      }
    ]
  }
]

4.2 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

9.0%

Related for CVELIST:CVE-2023-31413