PT-2017-18336 · Elastic · Cloud Enterprise

Publicado

2017-09-28

·

Atualizado

2019-10-09

·

CVE-2017-8444

CVSS v3.1

5.9

Média

VetorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Elastic Cloud Enterprise versions prior to 1.0.2
Description The issue concerns the client-forwarder in Elastic Cloud Enterprise, which does not properly encrypt traffic to ZooKeeper. This could allow an attacker to obtain sensitive data if they are able to perform a man-in-the-middle (MITM) attack on the traffic between the client-forwarder and ZooKeeper.
Recommendations For versions prior to 1.0.2, update to version 1.0.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the ZooKeeper endpoint to minimize the risk of exploitation.

Correção

Cleartext Transmission of Sensitive Information

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-8444

Produtos afetados

Cloud Enterprise