Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xr86-xwvg-mq5q

Опубликовано: 01 мая 2025
Источник: github
Github: Не прошло ревью
CVSS3: 6.2

Описание

Exposure of sensitive information to local unauthorized actors in Elastic Agent and Elastic Security Endpoint can lead to loss of confidentiality and impersonation of Endpoint to the Elastic Stack. This issue was identified by Elastic engineers and Elastic has no indication that it is known or has been exploited by malicious actors.

Exposure of sensitive information to local unauthorized actors in Elastic Agent and Elastic Security Endpoint can lead to loss of confidentiality and impersonation of Endpoint to the Elastic Stack. This issue was identified by Elastic engineers and Elastic has no indication that it is known or has been exploited by malicious actors.

EPSS

Процентиль: 8%
0.0003
Низкий

6.2 Medium

CVSS3

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 6.2
nvd
9 месяцев назад

Exposure of sensitive information to local unauthorized actors in Elastic Agent and Elastic Security Endpoint can lead to loss of confidentiality and impersonation of Endpoint to the Elastic Stack. This issue was identified by Elastic engineers and Elastic has no indication that it is known or has been exploited by malicious actors.

CVSS3: 6.2
fstec
9 месяцев назад

Уязвимость серверного программного средства управление агентами Elastic Agent и программного средства для защиты конечных точек Elastic Security Endpoint, связанная с недостаточной защитой служебных данных, позволяющая нарушителю оказать воздействие на конфиденциальность защищаемой информации

EPSS

Процентиль: 8%
0.0003
Низкий

6.2 Medium

CVSS3

Дефекты

CWE-200