CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2025-37729

CVSS 9.1v3.1pub. 2025-10-13upd. 2025-12-11

Improper neutralization of special elements used in a template engine in Elastic Cloud Enterprise (ECE) can lead to a malicious actor with Admin access exfiltrating sensitive information and issuing commands via a specially crafted string where Jinjava variables are evaluated.

🤖 AI Analysis
How it works

An attacker with administrator privileges in ECE can provide a specially crafted string containing Jinjava expressions (a template engine based on Java). The application processes this string without proper sanitization and evaluates the variables and template directives contained within it. As a result, it is possible to break out of the intended template context and execute unauthorized operations — both reading sensitive data and issuing system commands.

Impact

An attacker can exfiltrate sensitive information stored in the ECE environment and execute commands in the application context, which may lead to complete takeover of the attacked system.

Mitigation & patch

Elastic Cloud Enterprise should be updated to version 3.8.2 or 4.0.2 in accordance with security notice ESA-2025-21 available at: https://discuss.elastic.co/t/elastic-cloud-enterprise-ece-3-8-2-and-4-0-2-security-update-esa-2025-21/382641. Until the update is applied, access to the ECE administrator account should be restricted to trusted users only and the administrative panel should be secured at the network level.

Who is affected

Elastic Cloud Enterprise (ECE) — versions indicated in vendor references (vulnerability fixed in ECE 3.8.2 and 4.0.2)

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
  • Elastic Cloud Enterprise

    APP
    Elastic
    2.5.0 – 3.8.2 (excl.)4.0.0 – 4.0.2 (excl.)
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
CWE
References

Related vulnerabilities

CVE-2025-37736HIGH8.8same product

Improper Authorization in Elastic Cloud Enterprise can lead to Privilege Escalation where the built-in readonl...

CVE-2024-37282HIGH8.1same product

It was identified that under certain specific preconditions, an API key that was originally created with a spe...

CVE-2023-31418HIGH7.5same product

An issue has been identified with how Elasticsearch handled incoming requests on the HTTP layer. An unauthenti...

CVE-2018-3828HIGH7.5same product

Elastic Cloud Enterprise (ECE) versions prior to 1.1.4 contain an information exposure vulnerability. It was d...

CVE-2022-23716MEDIUM5.3same product

A flaw was discovered in ECE before 3.1.1 that could lead to the disclosure of the SAML signing private key us...