QID 731301
QID 731301: Elasticsearch Improper Authorization Vulnerability (ESA-2024-07)
Elasticsearch is a search server based on Lucene that provides a distributed, multitenant-capable full-text search engine with an HTTP web interface and schema-free JSON documents.
CVE-2024-23451: An incorrect Authorization issue exists in the API key-based security model for Remote Cluster Security which allows a malicious user with a valid API key for a remote cluster configured to use the new Remote Cluster Security to read arbitrary documents from any index on the remote cluster.
Affected Versions:
Elasticsearch versions from 8.10.0 to prior to 8.13.0
QID detection logic:
Checks the vulnerable versions of ElasticSearch.
Successful exploitation of this vulnerability may allows a malicious user with a valid API key for a remote cluster configured to use the new Remote Cluster Security to read arbitrary documents from any index on the remote cluster
CVEs related to QID 731301
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| ESA-2024-07 |
|