PT-2018-16220 · Elastic · Elasticsearch

Publicado

2018-09-19

·

Atualizado

2019-10-09

·

CVE-2018-3826

CVSS v3.1

6.5

Média

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Elasticsearch versions 6.0.0-beta1 through 6.2.4
Description A disclosure flaw was found in the snapshot API. When the access key and security key parameters are set using the snapshot API, they can be exposed as plain text by users able to query the snapshot API.
Recommendations For Elasticsearch versions 6.0.0-beta1 through 6.2.4, consider restricting access to the snapshot API to minimize the risk of exploitation. As a temporary workaround, avoid using the access key and security key parameters in the snapshot API until the issue is resolved.

Correção

Missing Encryption of Sensitive Data

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-3826

Produtos afetados

Elasticsearch