Intel

AIKIDO-2025-10687

elastic-transport is vulnerable to Insertion of Sensitive Information into Log File

Insertion of Sensitive Information into Log File Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Oct 9, 2025

20

Low Risk

This Affects:

Rubyelastic-transport
8.0.0 - 8.3.5
Fixed in 8.3.6
8.4.0 - 8.4.0
Fixed in 8.4.1
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to Information Disclosure due to unsanitized user input in URL and host parameters being directly set as OpenTelemetry span attributes. An attacker can exploit this by crafting malicious URLs containing special characters or payloads that, when processed by the monitoring system's telemetry backend, could lead to log injection, misinterpretation of telemetry data, or potential security incidents in downstream systems that consume these spans without proper sanitization.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

elastic-transport is vulnerable to Insertion of Sensitive Information into Log File in versions 8.4.0 - 8.4.0 and 8.0.0 - 8.3.5.

How to fix this

Upgrade the elastic-transport library to the patch version.