Description
Elasticsearch Alerting and Monitoring in versions before 6.4.1 or 5.6.12 have an information disclosure issue when secrets are configured via the API. The Elasticsearch _cluster/settings API, when queried, could leak sensitive configuration information such as passwords, tokens, or usernames. This could allow an authenticated Elasticsearch user to improperly view these details.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-5136 | Elasticsearch Alerting and Monitoring in versions before 6.4.1 or 5.6.12 have an information disclosure issue when secrets are configured via the API. The Elasticsearch _cluster/settings API, when queried, could leak sensitive configuration information such as passwords, tokens, or usernames. This could allow an authenticated Elasticsearch user to improperly view these details. |
Github GHSA |
GHSA-r9fv-qpm9-rj4g | Exposure of Sensitive Information to an Unauthorized Actor in Elasticsearch |
References
History
No history.
Status: PUBLISHED
Assigner: elastic
Published:
Updated: 2024-08-05T04:57:24.076Z
Reserved: 2018-01-02T00:00:00.000Z
Link: CVE-2018-3831
No data.
Status : Modified
Published: 2018-09-19T19:29:01.343
Modified: 2024-11-21T04:06:07.347
Link: CVE-2018-3831
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA