PT-2018-16219 · Elastic · Cloud Enterprise

Published

2018-09-19

·

Updated

2019-10-09

·

CVE-2018-3825

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Elastic Cloud Enterprise (ECE) versions prior to 1.1.4
Description A predictable default master encryption key is used in the process of granting ZooKeeper access to Elasticsearch clusters, unless explicitly overwritten. This key is the same across all ECE deployments. If an attacker can connect to ZooKeeper directly and the cluster ID is known, they would be able to access configuration information of other tenants.
Recommendations For versions prior to 1.1.4, update to version 1.1.4 or later to resolve the issue. As a temporary workaround, consider overwriting the default master encryption key to prevent predictability across deployments. Restrict access to ZooKeeper to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-3825

Affected Products

Cloud Enterprise