# Enterprise Search 8.11.2 / 7.17.16 Security Update (ESA-2023-31)

**URL:** <https://discuss.elastic.co/t/enterprise-search-8-11-2-7-17-16-security-update-esa-2023-31/349181>\
**Category:** Security Announcements\
**Created:** [December 12, 2023, 5:06pm UTC](https://discuss.elastic.co/t/enterprise-search-8-11-2-7-17-16-security-update-esa-2023-31/349181 "2023-12-12T17:06:41Z")\
**Posts on this page:** 1\
**Showing post:** 1

<div class="post-metadata">

**Author:** ![rodrigo\_silva](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rodrigo_silva/32/120546_2.png) [@rodrigo\_silva](https://discuss.elastic.co/u/rodrigo_silva)\
**Post date:** [December 12, 2023, 5:06pm UTC](https://discuss.elastic.co/t/enterprise-search-8-11-2-7-17-16-security-update-esa-2023-31/349181/1 "2023-12-12T17:06:41Z")

</div>

# Enterprise Search Insertion of Sensitive Information into Log File (ESA-2023-31)

An issue was discovered by Elastic whereby the [Documents API](https://www.elastic.co/guide/en/app-search/current/documents.html#documents-create) of App Search logged the raw contents of indexed documents at `INFO` log level. Depending on the contents of such documents, this could lead to the insertion of sensitive or private information in the App Search logs. Elastic has released 8.11.2 and 7.17.16 that resolves this issue by changing the log level at which these are logged to `DEBUG`, which is disabled by default.

**Affected Versions:**  
Enterprise Search versions on or after 7.0.0 and before 7.17.16.  
Enterprise Search versions on or after 8.0.0 and before 8.11.2.

**Affected Configurations:**  
Only users that directly utilize the [Documents API](https://www.elastic.co/guide/en/app-search/current/documents.html#documents-create) are affected by this issue, if the documents that they are ingesting via this API contain sensitive or private information.

**Solutions and Mitigations:**  
The issue is resolved in versions 7.17.16 and versions 8.11.2.

Customers on versions before 7.17.16 and 8.11.2 that cannot upgrade can prohibit document contents from being logged by setting [log\_level](https://www.elastic.co/guide/en/enterprise-search/current/configuration.html#configuration-settings-logging) to `WARN` or higher in their Enterprise Search configuration. Refer to [our documentation](https://www.elastic.co/guide/en/enterprise-search/current/configuration.html#configuration-configure) for applying this setting on Elastic Cloud, ECE or self managed clusters.

**Severity:**  
CVSSv3.1: 6.8(Medium) - [AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N](https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N)  
CVE ID: CVE-2023-49923

---

_[View the full topic](https://discuss.elastic.co/t/enterprise-search-8-11-2-7-17-16-security-update-esa-2023-31/349181)._
