Elastic
Elastic APM Server: vulnerabilidades y CVE
Elastic APM Server tiene 5 vulnerabilidades publicadas, 1 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE5
Últimos 12 meses1
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-78594 | Media (4.9) | 0.50% | — | 2 sept 2026 | Improper Handling of Highly Compressed Data (CWE-409) in APM Server can lead to a persistent denial of service via Excessive Allocation (CAPEC-130). An authenticated user with write access to source map content could… |
| CVE-2024-11994 | Media (5.7) | 0.26% | — | 1 may 2025 | APM server logs could contain parts of the document body from a partially failed bulk index request. Depending on the nature of the document, this could disclose sensitive information in APM Server error logs. |
| CVE-2024-37286 | Media (6.5) | 0.49% | — | 3 ago 2024 | APM server logs contain document body from a partially failed bulk index request. For example, in case of unavailable_shards_exception for a specific document, since the ES response line contains the document body, and… |
| CVE-2024-23448 | Alta (7.5) | 0.67% | — | 7 feb 2024 | An issue was discovered whereby APM Server could log at ERROR level, a response from Elasticsearch indicating that indexing the document failed and that response would contain parts of the original document. Depending… |
| CVE-2023-31421 | Alta (7.5) | 0.32% | — | 26 oct 2023 | It was discovered that when acting as TLS clients, Beats, Elastic Agent, APM Server, and Fleet Server did not verify whether the server certificate is valid for the target IP address; however, certificate signature… |