Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-59qp-8h5f-h6h4

Опубликовано: 26 окт. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 4.6

Описание

If Elastic Endpoint (v7.9.0 - v8.10.3) is configured to use a non-default option in which the logging level is explicitly set to debug, and when Elastic Agent is simultaneously configured to collect and send those logs to Elasticsearch, then Elastic Agent API keys can be viewed in Elasticsearch in plaintext. These API keys could be used to write arbitrary data and read Elastic Endpoint user artifacts.

If Elastic Endpoint (v7.9.0 - v8.10.3) is configured to use a non-default option in which the logging level is explicitly set to debug, and when Elastic Agent is simultaneously configured to collect and send those logs to Elasticsearch, then Elastic Agent API keys can be viewed in Elasticsearch in plaintext. These API keys could be used to write arbitrary data and read Elastic Endpoint user artifacts.

EPSS

Процентиль: 60%
0.00403
Низкий

4.6 Medium

CVSS3

Дефекты

CWE-532

Связанные уязвимости

CVSS3: 4.6
nvd
больше 2 лет назад

If Elastic Endpoint (v7.9.0 - v8.10.3) is configured to use a non-default option in which the logging level is explicitly set to debug, and when Elastic Agent is simultaneously configured to collect and send those logs to Elasticsearch, then Elastic Agent API keys can be viewed in Elasticsearch in plaintext. These API keys could be used to write arbitrary data and read Elastic Endpoint user artifacts.

CVSS3: 4.6
fstec
больше 2 лет назад

Уязвимость программного средства для защиты конечных точек Elastic Endpoint, связанная с недостаточной защитой регистрационных данных, позволяющая нарушителю раскрыть защищаемую информацию

EPSS

Процентиль: 60%
0.00403
Низкий

4.6 Medium

CVSS3

Дефекты

CWE-532