# APM Server 8.14.0 Security Update (ESA-2024-19)

**URL:** <https://discuss.elastic.co/t/apm-server-8-14-0-security-update-esa-2024-19/364289>\
**Category:** Security Announcements\
**Created:** [August 2, 2024, 8:20pm UTC](https://discuss.elastic.co/t/apm-server-8-14-0-security-update-esa-2024-19/364289 "2024-08-02T20:20:04Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![rodrigo\_silva](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rodrigo_silva/32/120546_2.png) [@rodrigo\_silva](https://discuss.elastic.co/u/rodrigo_silva)\
**Post date:** [August 2, 2024, 8:20pm UTC](https://discuss.elastic.co/t/apm-server-8-14-0-security-update-esa-2024-19/364289/1 "2024-08-02T20:20:04Z")

</div>

### APM Server Insertion of Sensitive Information into Log File (ESA-2024-19)

APM server logs contain document body from a partially failed bulk index request. For example, in case of unavailable\_shards\_exception for a specific document, since the ES response line contains the document body, and that APM server logs the ES response line on error, the document is effectively logged.

**Affected Versions:**  
APM Server versions before 8.14.0

**Solutions and Mitigations:**  
The issue is resolved in version 8.14.0.

**Reviewing Logs for Sensitive Information**  
Users can search for instances of these documents and determine whether any sensitive information has been leaked in APM Server logs by searching for the following string

​​`message: "unavailable_shards_exception"` and `message: "source"`

**Severity:** CVSSv3: 5.7(Medium) - [AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N](https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N)

**CVE ID:** CVE-2024-37286
