Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-23708

Опубликовано: 28 фев. 2022
Источник: redhat
CVSS3: 4.3
EPSS Низкий

Описание

A flaw was discovered in Elasticsearch 7.17.0’s upgrade assistant, in which upgrading from version 6.x to 7.x would disable the in-built protections on the security index, allowing authenticated users with “*” index permissions access to this index.

A flaw was found in the upgrade assistant for Elasticsearch. When upgrading from version 6.x to 7.x, the built-in protections on the security index are disabled, allowing authenticated users to access the index.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Logging Subsystem for Red Hat OpenShiftopenshift-logging/elasticsearch6-rhel8Will not fix
OpenShift Service Mesh 2.0servicemesh-grafanaAffected
OpenShift Service Mesh 2.1servicemesh-grafanaWill not fix
Red Hat Decision Manager 7elasticsearchNot affected
Red Hat Fuse 7elasticsearchNot affected
Red Hat Integration Camel K 1elasticsearchNot affected
Red Hat JBoss Data Grid 6elasticsearchOut of support scope
Red Hat JBoss Fuse 6elasticsearchOut of support scope
Red Hat JBoss Fuse Service Works 6elasticsearchOut of support scope
Red Hat OpenShift Container Platform 3.11openshift3/ose-logging-elasticsearch5Will not fix

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-273
https://bugzilla.redhat.com/show_bug.cgi?id=2066385elasticsearch: privilege escalation vulnerability (ESA-2022-02)

EPSS

Процентиль: 47%
0.00245
Низкий

4.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.3
ubuntu
почти 4 года назад

A flaw was discovered in Elasticsearch 7.17.0’s upgrade assistant, in which upgrading from version 6.x to 7.x would disable the in-built protections on the security index, allowing authenticated users with “*” index permissions access to this index.

CVSS3: 4.3
nvd
почти 4 года назад

A flaw was discovered in Elasticsearch 7.17.0’s upgrade assistant, in which upgrading from version 6.x to 7.x would disable the in-built protections on the security index, allowing authenticated users with “*” index permissions access to this index.

CVSS3: 4.3
debian
почти 4 года назад

A flaw was discovered in Elasticsearch 7.17.0\u2019s upgrade assistant ...

CVSS3: 4.3
github
почти 4 года назад

Elasticsearch privilege escalation

EPSS

Процентиль: 47%
0.00245
Низкий

4.3 Medium

CVSS3