Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2017-8442

Опубликовано: 07 июл. 2017
Источник: nvd
CVSS3: 6.5
CVSS2: 4
EPSS Низкий

Описание

Elasticsearch X-Pack Security versions 5.0.0 to 5.4.3, when enabled, can result in the Elasticsearch _nodes API leaking sensitive configuration information, such as the paths and passphrases of SSL keys that were configured as part of an authentication realm. This could allow an authenticated Elasticsearch user to improperly view these details.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:elastic:x-pack:*:*:*:*:*:*:*:*
Версия от 5.0.0 (включая) до 5.4.3 (включая)

EPSS

Процентиль: 62%
0.00427
Низкий

6.5 Medium

CVSS3

4 Medium

CVSS2

Дефекты

CWE-402
CWE-200

Связанные уязвимости

CVSS3: 6.5
github
больше 3 лет назад

Elasticsearch X-Pack Security versions 5.0.0 to 5.4.3, when enabled, can result in the Elasticsearch _nodes API leaking sensitive configuration information, such as the paths and passphrases of SSL keys that were configured as part of an authentication realm. This could allow an authenticated Elasticsearch user to improperly view these details.

EPSS

Процентиль: 62%
0.00427
Низкий

6.5 Medium

CVSS3

4 Medium

CVSS2

Дефекты

CWE-402
CWE-200