CNNVD-202510-1668 Information

CNNVD ID

CNNVD-202510-1668

CVE-2025-37729

  • CNNVD Published: 2025-10-13

Description (Chinese)

Elastic Cloud Enterprise是荷兰Elastic公司的一种云平台。使在云中部署、操作和扩展 Elastic Stack 变得容易。 Elastic Cloud Enterprise存在安全漏洞,该漏洞源于模板引擎中特殊元素中和不当,可能导致管理员权限的攻击者通过特制字符串窃取敏感信息和执行命令。

Description (English)

Elastic Cloud Enterprise is a cloud platform for the Dutch company Elastic. It makes it easier to deploy, operate and expand Elastic Stack in the clouds. There is a security loophole in Elastic Cloud Enterprise, which stems from the inaccuracy of special elements in the template engine, which may lead the assailant of the administrator ’ s authority to steal sensitive information and execute orders through a special string.

Hazard Level

High

Vulnerability Type

其他

Affected Vendor

Elastic

Published

2025-10-13

Last Modified

2026-02-24

References

https://discuss.elastic.co/t/elastic-cloud-enterprise-ece-3-8-2-and-4-0-2-security-update-esa-2025-21/382641 https://access.redhat.com/security/cve/cve-2025-37729

Patch

https://discuss.elastic.co/t/elastic-cloud-enterprise-ece-3-8-2-and-4-0-2-security-update-esa-2025-21/382641

Share on: