Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-m9gh-789g-q5pv

Опубликовано: 15 дек. 2025
Источник: github
Github: Прошло ревью
CVSS3: 6.8

Описание

Elasticsearch PKI Realm Authentication Bypass Vulnerability Allows User Impersonation Through Crafted Client Certificates

Improper Authentication in Elasticsearch PKI realm can lead to user impersonation via specially crafted client certificates. A malicious actor would need to have such a crafted client certificate signed by a legitimate, trusted Certificate Authority.

Пакеты

Наименование

org.elasticsearch:elasticsearch

maven
Затронутые версииВерсия исправления

>= 7.0.0-alpha1, < 8.19.8

8.19.8

Наименование

org.elasticsearch:elasticsearch

maven
Затронутые версииВерсия исправления

>= 9.0.0-beta1, < 9.1.8

9.1.8

Наименование

org.elasticsearch:elasticsearch

maven
Затронутые версииВерсия исправления

>= 9.2.0, < 9.2.2

9.2.2

EPSS

Процентиль: 9%
0.00033
Низкий

6.8 Medium

CVSS3

Дефекты

CWE-287
CWE-295

Связанные уязвимости

CVSS3: 6.8
ubuntu
около 2 месяцев назад

Improper Authentication in Elasticsearch PKI realm can lead to user impersonation via specially crafted client certificates. A malicious actor would need to have such a crafted client certificate signed by a legitimate, trusted Certificate Authority.

CVSS3: 6.8
nvd
около 2 месяцев назад

Improper Authentication in Elasticsearch PKI realm can lead to user impersonation via specially crafted client certificates. A malicious actor would need to have such a crafted client certificate signed by a legitimate, trusted Certificate Authority.

msrc
около 2 месяцев назад

Elasticsearch Improper Authentication

CVSS3: 6.8
debian
около 2 месяцев назад

Improper Authentication in Elasticsearch PKI realm can lead to user im ...

EPSS

Процентиль: 9%
0.00033
Низкий

6.8 Medium

CVSS3

Дефекты

CWE-287
CWE-295