Fleet Server 8.15.0 Security Update ( ESA-2024-31)

Fleet Server sensitive information exposure via logs (ESA-2024-31)

An issue was identified in Fleet Server where Fleet policies that could contain sensitive information were logged on INFO and ERROR log levels. The nature of the sensitive information largely depends on the integrations enabled.

Affected Versions:

Fleet Server versions from 8.13.0 up to 8.15.0

Solutions and Mitigations:

Users should upgrade to version 8.15.0

Severity: CVSSv3.1: 9.0 (Critical) - CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CVE ID: CVE-2024-52975

1 Like