PT-2018-16220 · Elastic · Elasticsearch
Published
2018-09-19
·
Updated
2019-10-09
·
CVE-2018-3826
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Elasticsearch versions 6.0.0-beta1 through 6.2.4
Description
A disclosure flaw was found in the snapshot API. When the
access key and security key parameters are set using the snapshot API, they can be exposed as plain text by users able to query the snapshot API.Recommendations
For Elasticsearch versions 6.0.0-beta1 through 6.2.4, consider restricting access to the snapshot API to minimize the risk of exploitation. As a temporary workaround, avoid using the
access key and security key parameters in the snapshot API until the issue is resolved.Fix
Missing Encryption of Sensitive Data
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Elasticsearch