CVE-2018-3827: Elastic Azure Repository

High severity, CVSS 8.1. EPSS: 1% chance of exploitation in the next 30 days.

A sensitive data disclosure flaw was found in the Elasticsearch repository-azure (formerly elasticsearch-cloud-azure) plugin. When the repository-azure plugin is set to log at TRACE level Azure credentials can be inadvertently logged.

Affected products

  • Elastic Azure Repository: from 6.0.1, up to and including 6.2.4; version 6.0.0 only

Published 2018-09-19. Last modified 2026-06-17.