Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2025-37731

Опубликовано: 15 дек. 2025
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 6.8

Описание

Improper Authentication in Elasticsearch PKI realm can lead to user impersonation via specially crafted client certificates. A malicious actor would need to have such a crafted client certificate signed by a legitimate, trusted Certificate Authority.

РелизСтатусПримечание
devel

DNE

esm-apps-legacy/xenial

needs-triage

esm-apps/xenial

ignored

end of ESM support, was needs-triage
jammy

DNE

noble

DNE

plucky

DNE

questing

DNE

resolute

DNE

upstream

needs-triage

Показывать по

EPSS

Процентиль: 9%
0.00194
Низкий

6.8 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.4
redhat
8 месяцев назад

Improper Authentication in Elasticsearch PKI realm can lead to user impersonation via specially crafted client certificates. A malicious actor would need to have such a crafted client certificate signed by a legitimate, trusted Certificate Authority.

CVSS3: 6.8
nvd
8 месяцев назад

Improper Authentication in Elasticsearch PKI realm can lead to user impersonation via specially crafted client certificates. A malicious actor would need to have such a crafted client certificate signed by a legitimate, trusted Certificate Authority.

msrc
12 дней назад

Elasticsearch Improper Authentication

CVSS3: 6.8
debian
8 месяцев назад

Improper Authentication in Elasticsearch PKI realm can lead to user im ...

CVSS3: 6.8
github
8 месяцев назад

Elasticsearch PKI Realm Authentication Bypass Vulnerability Allows User Impersonation Through Crafted Client Certificates

EPSS

Процентиль: 9%
0.00194
Низкий

6.8 Medium

CVSS3