A flaw was discovered in Elasticsearch 7.17.0’s upgrade assistant, in which upgrading from version 6.x to 7.x would disable the in-built protections on the security index, allowing authenticated users with “*” index permissions access to this index.
References
Configurations
Information
Published : 2022-03-03 22:15
Updated : 2022-07-29 20:15
NVD link : CVE-2022-23708
Mitre link : CVE-2022-23708
JSON object : View
Products Affected
elastic
- elasticsearch
CWE
CWE-269
Improper Privilege Management
