A flaw was found in all Openshift Enterprise versions using the openshift elasticsearch plugin. An attacker with knowledge of the given name used to authenticate and access Elasticsearch can later access it without the token, bypassing authentication. This attack also requires that the Elasticsearch be configured with an external route, and the data accessed is limited to the indices.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published: 2018-07-27T15:00:00

Updated: 2024-08-05T18:28:16.605Z

Reserved: 2017-08-01T00:00:00

Link: CVE-2017-12195

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2018-07-27T15:29:00.297

Modified: 2023-02-12T23:28:16.177

Link: CVE-2017-12195

cve-icon Redhat

Severity : Moderate

Publid Date: 2017-11-28T00:00:00Z

Links: CVE-2017-12195 - Bugzilla