Vulnerability Name: | CVE-2018-3828 (CCN-150281) | ||||||||||||
Assigned: | 2018-06-13 | ||||||||||||
Published: | 2018-06-13 | ||||||||||||
Updated: | 2019-10-09 | ||||||||||||
Summary: | Elastic Cloud Enterprise (ECE) versions prior to 1.1.4 contain an information exposure vulnerability. It was discovered that certain exception conditions would result in encryption keys, passwords, and other security sensitive headers being leaked to the allocator logs. An attacker with access to the logging cluster may obtain leaked credentials and perform authenticated actions using these credentials. | ||||||||||||
CVSS v3 Severity: | 7.5 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H) 6.5 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
5.7 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C)
| ||||||||||||
CVSS v2 Severity: | 3.5 Low (CVSS v2 Vector: AV:N/AC:M/Au:S/C:P/I:N/A:N)
| ||||||||||||
Vulnerability Type: | CWE-532 | ||||||||||||
Vulnerability Consequences: | Obtain Information | ||||||||||||
References: | Source: MITRE Type: CNA CVE-2018-3828 Source: CCN Type: Elastic Web site Elastic Cloud Enterprise 1.1.4 security update Source: CONFIRM Type: Vendor Advisory https://discuss.elastic.co/t/elastic-cloud-enterprise-1-1-4-security-update/135778 Source: XF Type: UNKNOWN elastic-cve20183828-info-disc(150281) Source: CONFIRM Type: Vendor Advisory https://www.elastic.co/community/security | ||||||||||||
Vulnerable Configuration: | Configuration 1: Denotes that component is vulnerable | ||||||||||||
BACK |