Intel

AIKIDO-2025-10059

applicationinsights-agent is vulnerable to Insertion of Sensitive Information into Log File

Insertion of Sensitive Information into Log File Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.

17

Low Risk

This Affects:

JAVAapplicationinsights-agent
3.4.5 - 3.6.2
Fixed in 3.7.0

TL;DR

Affected versions of this package may expose user passwords or tokens in logs generated by the self-diagnostics feature of the agent tooling. This occurs due to improper redaction of sensitive information, potentially allowing unauthorized access to credentials if logs are accessed by malicious actors.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

applicationinsights-agent is vulnerable to Insertion of Sensitive Information into Log File in versions 3.4.5 - 3.6.2.

How to fix this

Upgrade the com.microsoft.azure:applicationinsights-agent library to the patch version.