Логотип exploitDog
bind:CVE-2024-23451
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-23451

Количество 6

Количество 6

ubuntu логотип

CVE-2024-23451

почти 2 года назад

Incorrect Authorization issue exists in the API key based security model for Remote Cluster Security, which is currently in Beta, in Elasticsearch 8.10.0 and before 8.13.0. This allows a malicious user with a valid API key for a remote cluster configured to use the new Remote Cluster Security to read arbitrary documents from any index on the remote cluster, and only if they use the Elasticsearch custom transport protocol to issue requests with the target index ID, the shard ID and the document ID. None of Elasticsearch REST API endpoints are affected by this issue.

CVSS3: 4.4
EPSS: Низкий
redhat логотип

CVE-2024-23451

почти 2 года назад

Incorrect Authorization issue exists in the API key based security model for Remote Cluster Security, which is currently in Beta, in Elasticsearch 8.10.0 and before 8.13.0. This allows a malicious user with a valid API key for a remote cluster configured to use the new Remote Cluster Security to read arbitrary documents from any index on the remote cluster, and only if they use the Elasticsearch custom transport protocol to issue requests with the target index ID, the shard ID and the document ID. None of Elasticsearch REST API endpoints are affected by this issue.

CVSS3: 4.4
EPSS: Низкий
nvd логотип

CVE-2024-23451

почти 2 года назад

Incorrect Authorization issue exists in the API key based security model for Remote Cluster Security, which is currently in Beta, in Elasticsearch 8.10.0 and before 8.13.0. This allows a malicious user with a valid API key for a remote cluster configured to use the new Remote Cluster Security to read arbitrary documents from any index on the remote cluster, and only if they use the Elasticsearch custom transport protocol to issue requests with the target index ID, the shard ID and the document ID. None of Elasticsearch REST API endpoints are affected by this issue.

CVSS3: 4.4
EPSS: Низкий
debian логотип

CVE-2024-23451

почти 2 года назад

Incorrect Authorization issue exists in the API key based security mod ...

CVSS3: 4.4
EPSS: Низкий
github логотип

GHSA-r3hx-qfh5-r9m7

почти 2 года назад

Elasticsearch Incorrect Authorization vulnerability

CVSS3: 4.4
EPSS: Низкий
fstec логотип

BDU:2024-02657

около 2 лет назад

Уязвимость компонента Remote Cluster Security поисковой системы Elasticsearch, связанная с неправильной авторизацией, позволяющая нарушителю получить доступ к защищаемой информации

CVSS3: 4.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2024-23451

Incorrect Authorization issue exists in the API key based security model for Remote Cluster Security, which is currently in Beta, in Elasticsearch 8.10.0 and before 8.13.0. This allows a malicious user with a valid API key for a remote cluster configured to use the new Remote Cluster Security to read arbitrary documents from any index on the remote cluster, and only if they use the Elasticsearch custom transport protocol to issue requests with the target index ID, the shard ID and the document ID. None of Elasticsearch REST API endpoints are affected by this issue.

CVSS3: 4.4
0%
Низкий
почти 2 года назад
redhat логотип
CVE-2024-23451

Incorrect Authorization issue exists in the API key based security model for Remote Cluster Security, which is currently in Beta, in Elasticsearch 8.10.0 and before 8.13.0. This allows a malicious user with a valid API key for a remote cluster configured to use the new Remote Cluster Security to read arbitrary documents from any index on the remote cluster, and only if they use the Elasticsearch custom transport protocol to issue requests with the target index ID, the shard ID and the document ID. None of Elasticsearch REST API endpoints are affected by this issue.

CVSS3: 4.4
0%
Низкий
почти 2 года назад
nvd логотип
CVE-2024-23451

Incorrect Authorization issue exists in the API key based security model for Remote Cluster Security, which is currently in Beta, in Elasticsearch 8.10.0 and before 8.13.0. This allows a malicious user with a valid API key for a remote cluster configured to use the new Remote Cluster Security to read arbitrary documents from any index on the remote cluster, and only if they use the Elasticsearch custom transport protocol to issue requests with the target index ID, the shard ID and the document ID. None of Elasticsearch REST API endpoints are affected by this issue.

CVSS3: 4.4
0%
Низкий
почти 2 года назад
debian логотип
CVE-2024-23451

Incorrect Authorization issue exists in the API key based security mod ...

CVSS3: 4.4
0%
Низкий
почти 2 года назад
github логотип
GHSA-r3hx-qfh5-r9m7

Elasticsearch Incorrect Authorization vulnerability

CVSS3: 4.4
0%
Низкий
почти 2 года назад
fstec логотип
BDU:2024-02657

Уязвимость компонента Remote Cluster Security поисковой системы Elasticsearch, связанная с неправильной авторизацией, позволяющая нарушителю получить доступ к защищаемой информации

CVSS3: 4.4
0%
Низкий
около 2 лет назад

Уязвимостей на страницу