QID 730387
Date Published: 2022-03-09
QID 730387: Elasticsearch Insecure Permission Vulnerability (ESA-2022-02)
Elasticsearch is a search server based on Lucene that provides a distributed, multitenant-capable full-text search engine with an HTTP web interface and schema-free JSON documents.
CVE-2022-23708: A flaw was discovered in Elasticsearch 7.17.0's upgrade assistant, in which upgrading from version 6.x to 7.x would disable the in-built protections on the security index, allowing authenticated users with "*" index permissions access.
Affected Versions:
Elasticsearch versions from 7.16 prior to 7.17.1
QID detection logic:
Checks the vulnerable versions of ElasticSearch.
Successful exploitation of this vulnerability may allow an authenticated attacker to gain access to unauthorized data.
Solution
Customers are advised to upgrade to Elasticsearch version 7.17.1 to remediate this vulnerability.
Vendor References
- ESA-2022-02 -
www.elastic.co/community/security/
CVEs related to QID 730387
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| ESA-2022-02 |
|