# Fleet Server 8.15.0 Security Update ( ESA-2024-31)

**URL:** https://discuss.elastic.co/t/fleet-server-8-15-0-security-update-esa-2024-31/373522
**Category:** Security Announcements
**Created:** [January 22, 2025, 3:09pm UTC](https://discuss.elastic.co/t/fleet-server-8-15-0-security-update-esa-2024-31/373522 "2025-01-22T15:09:01Z")
**Posts on this page:** 1
**Page:** 1

<div class="post-metadata">

### Author: ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)
#### Post date: [January 22, 2025, 3:09pm UTC](https://discuss.elastic.co/t/fleet-server-8-15-0-security-update-esa-2024-31/373522/1 "2025-01-22T15:09:01Z")

</div>

### Fleet Server sensitive information exposure via logs (ESA-2024-31)

An issue was identified in Fleet Server where Fleet policies that could contain sensitive information were logged on INFO and ERROR log levels. The nature of the sensitive information largely depends on the integrations enabled.

### Affected Versions:

Fleet Server versions from 8.13.0 up to 8.15.0

### Solutions and Mitigations:

Users should upgrade to version 8.15.0

**Severity** : CVSSv3.1: 9.0 (Critical) - CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H  
**CVE ID** : CVE-2024-52975
