Elasticsearch X-Pack Security versions 5.0.0 to 5.4.3, when enabled, can result in the Elasticsearch _nodes API leaking sensitive configuration information, such as the paths and passphrases of SSL keys that were configured as part of an authentication realm. This could allow an authenticated Elasticsearch user to improperly view these details.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2017-17393 | Elasticsearch X-Pack Security versions 5.0.0 to 5.4.3, when enabled, can result in the Elasticsearch _nodes API leaking sensitive configuration information, such as the paths and passphrases of SSL keys that were configured as part of an authentication realm. This could allow an authenticated Elasticsearch user to improperly view these details. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://www.elastic.co/community/security |
|
History
No history.
Status: PUBLISHED
Assigner: elastic
Published:
Updated: 2024-08-05T16:34:23.206Z
Reserved: 2017-05-02T00:00:00
Link: CVE-2017-8442
No data.
Status : Deferred
Published: 2017-07-07T20:29:00.177
Modified: 2025-04-20T01:37:25.860
Link: CVE-2017-8442
No data.
OpenCVE Enrichment
No data.
EUVD