PT-2018-16220 · Elastic · Elasticsearch

Published

2018-09-19

·

Updated

2019-10-09

·

CVE-2018-3826

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Elasticsearch versions 6.0.0-beta1 through 6.2.4
Description A disclosure flaw was found in the snapshot API. When the access key and security key parameters are set using the snapshot API, they can be exposed as plain text by users able to query the snapshot API.
Recommendations For Elasticsearch versions 6.0.0-beta1 through 6.2.4, consider restricting access to the snapshot API to minimize the risk of exploitation. As a temporary workaround, avoid using the access key and security key parameters in the snapshot API until the issue is resolved.

Fix

Missing Encryption of Sensitive Data

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-3826

Affected Products

Elasticsearch