CVE-2022-23716
Summary
| CVE | CVE-2022-23716 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-09-28 20:15:00 UTC |
| Updated | 2022-09-30 18:14:00 UTC |
| Description | A flaw was discovered in ECE before 3.1.1 that could lead to the disclosure of the SAML signing private key used for the RBAC features, in deployment logs in the Logging and Monitoring cluster. |
Risk And Classification
Problem Types: CWE-532
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Elastic | Elastic Cloud Enterprise | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Security issues | Elastic | MISC | www.elastic.co | |
| Elastic Cloud Enterprise 3.1.1 Security Update - Security Announcements - Discuss the Elastic Stack | MISC | discuss.elastic.co | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.