In Elastic Cloud Enterprise (ECE) versions prior to 1.1.4 a default master encryption key is used in the process of granting ZooKeeper access to Elasticsearch clusters. Unless explicitly overwritten, this master key is predictable across all ECE deployments. If an attacker can connect to ZooKeeper directly they would be able to access configuration information of other tenants if their cluster ID is known.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: elastic
Published: 2018-09-19T19:00:00
Updated: 2024-08-05T04:57:24.044Z
Reserved: 2018-01-02T00:00:00
Link: CVE-2018-3825
Vulnrichment
No data.
NVD
Status : Modified
Published: 2018-09-19T19:29:00.500
Modified: 2024-11-21T04:06:06.577
Link: CVE-2018-3825
Redhat
No data.