---
cve: "CVE-2024-52975"
severity: "CRITICAL"
cvss: 9.0
epss: "27%"
vendor: "Elastic"
kev: false
exploited: false
published: "2025-01-23 07:19:39"
tags: [cve, security, critical]
source: tsecurity.de CVE-Dossier
exported: "2026-09-05T19:20:41+02:00"
---

# CVE-2024-52975

> 9.0 CRITICAL

## Beschreibung

An issue was identified in Fleet Server where Fleet policies that could contain sensitive information were logged on INFO and ERROR log levels. The nature of the sensitive information largely depends on the integrations enabled.

## CVSS-Vektor

```
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Benachbart | warn |
| AC Komplexität | Gering | bad |
| PR Privilegien | Gering | warn |
| UI Interaktion | Keine | bad |
| S Scope | Verändert | bad |
| C Vertraulichkeit | Hoch | bad |
| I Integrität | Hoch | bad |
| A Verfügbarkeit | Hoch | bad |

## Referenzen

- <https://discuss.elastic.co/t/fleet-server-8-15-0-security-update-esa-2024-31/373522>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2024-52975) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
