Vulnerability Name: | CVE-2022-23715 (CCN-234460) | ||||||||||||
Assigned: | 2022-08-24 | ||||||||||||
Published: | 2022-08-24 | ||||||||||||
Updated: | 2022-08-31 | ||||||||||||
Summary: | A flaw was discovered in ECE before 3.4.0 that might lead to the disclosure of sensitive information such as user passwords and Elasticsearch keystore settings values in logs such as the audit log or deployment logs in the Logging and Monitoring cluster. The affected APIs are PATCH /api/v1/user and PATCH /deployments/{deployment_id}/elasticsearch/{ref_id}/keystore | ||||||||||||
CVSS v3 Severity: | 6.5 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N) 5.7 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C)
7.4 High (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N/E:U/RL:O/RC:C)
| ||||||||||||
CVSS v2 Severity: | 7.5 High (CCN CVSS v2 Vector: AV:N/AC:L/Au:S/C:C/I:P/A:N)
| ||||||||||||
Vulnerability Type: | CWE-532 | ||||||||||||
Vulnerability Consequences: | Obtain Information | ||||||||||||
References: | Source: MITRE Type: CNA CVE-2022-23715 Source: CCN Type: Elasticsearch ESA-2022-10 Elastic Cloud Enterprise Sensitive information disclosure issue Source: MISC Type: Vendor Advisory https://discuss.elastic.co/t/elastic-cloud-enterprise-3-4-0-security-update/312825 Source: XF Type: UNKNOWN elasticsearch-cve202223715-info-disc(234460) Source: MISC Type: Vendor Advisory https://www.elastic.co/community/security | ||||||||||||
Vulnerable Configuration: | Configuration 1:![]() | ||||||||||||
BACK |