CVE-2025-37729 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

Improper neutralization of special elements used in a template engine in Elastic Cloud Enterprise (ECE) can lead to a malicious actor with Admin access exfiltra…
Critical CVSS: 9.1

CVE-2025-37729

Improper neutralization of special elements used in a template engine in Elastic Cloud Enterprise (ECE) can lead to a malicious actor with Admin access exfiltrating sensitive information and issuing commands via a specially crafted string where Jinjava variables are evaluated.
Vendor
Elastic
Product
Elastic Cloud Enterprise
CWE
CWE-1336
Yayın Tarihi
2025-10-13 14:15:34
Güncelleme
2025-12-11 20:59:06
Source Identifier
security@elastic.co
KEV Date Added
-

Kategoriler

Referanslar