An error was found in the X-Pack Security TLS trust manager for versions 5.0.0 to 5.5.1. If reloading the trust material fails the trust manager will be replaced with an instance that trusts all certificates. This could allow any node using any certificate to join a cluster. The proper behavior in this instance is for the TLS trust manager to deny all certificates.
Metrics
Affected Vendors & Products
Advisories
Source | ID | Title |
---|---|---|
![]() |
EUVD-2017-17396 | An error was found in the X-Pack Security TLS trust manager for versions 5.0.0 to 5.5.1. If reloading the trust material fails the trust manager will be replaced with an instance that trusts all certificates. This could allow any node using any certificate to join a cluster. The proper behavior in this instance is for the TLS trust manager to deny all certificates. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
Link | Providers |
---|---|
https://www.elastic.co/community/security |
![]() ![]() |
History
No history.

Status: PUBLISHED
Assigner: elastic
Published:
Updated: 2024-08-05T16:34:23.276Z
Reserved: 2017-05-02T00:00:00
Link: CVE-2017-8445

No data.

Status : Deferred
Published: 2017-08-18T20:29:00.257
Modified: 2025-04-20T01:37:25.860
Link: CVE-2017-8445

No data.

No data.