PT-2018-16220 · Elastic · Elasticsearch
Publicado
2018-09-19
·
Atualizado
2019-10-09
·
CVE-2018-3826
CVSS v3.1
6.5
Média
| Vetor | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Elasticsearch versions 6.0.0-beta1 through 6.2.4
Description
A disclosure flaw was found in the snapshot API. When the
access key and security key parameters are set using the snapshot API, they can be exposed as plain text by users able to query the snapshot API.Recommendations
For Elasticsearch versions 6.0.0-beta1 through 6.2.4, consider restricting access to the snapshot API to minimize the risk of exploitation. As a temporary workaround, avoid using the
access key and security key parameters in the snapshot API until the issue is resolved.Correção
Missing Encryption of Sensitive Data
Information Disclosure
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Elasticsearch