QID 730387

Date Published: 2022-03-09

QID 730387: Elasticsearch Insecure Permission Vulnerability (ESA-2022-02)

Elasticsearch is a search server based on Lucene that provides a distributed, multitenant-capable full-text search engine with an HTTP web interface and schema-free JSON documents.

CVE-2022-23708: A flaw was discovered in Elasticsearch 7.17.0's upgrade assistant, in which upgrading from version 6.x to 7.x would disable the in-built protections on the security index, allowing authenticated users with "*" index permissions access.

Affected Versions:
Elasticsearch versions from 7.16 prior to 7.17.1

QID detection logic:
Checks the vulnerable versions of ElasticSearch.

Successful exploitation of this vulnerability may allow an authenticated attacker to gain access to unauthorized data.

  • CVSS V3 rated as Medium - 4.3 severity.
  • CVSS V2 rated as Medium - 4 severity.
  • Solution
    Customers are advised to upgrade to Elasticsearch version 7.17.1 to remediate this vulnerability.
    Vendor References

    CVEs related to QID 730387

    Software Advisories
    Advisory ID Software Component Link
    ESA-2022-02 URL Logo www.elastic.co/community/security/