Description
Secret token configuration is never applied when using ECK <2.8 with APM Server >=8.0. This could lead to anonymous requests to an APM Server being accepted and the data ingested into this APM deployment.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-35727 | Secret token configuration is never applied when using ECK <2.8 with APM Server >=8.0. This could lead to anonymous requests to an APM Server being accepted and the data ingested into this APM deployment. |
References
History
No history.
Status: PUBLISHED
Assigner: elastic
Published:
Updated: 2024-09-09T16:16:37.729Z
Reserved: 2023-04-27T18:54:56.704Z
Link: CVE-2023-31416
Updated: 2024-08-02T14:53:30.908Z
Status : Modified
Published: 2023-10-26T19:15:45.270
Modified: 2024-11-21T08:01:49.107
Link: CVE-2023-31416
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD