CVE-2018-3826
19.09.2018, 19:29
In Elasticsearch versions 6.0.0-beta1 to 6.2.4 a disclosure flaw was found in the _snapshot API. When the access_key and security_key parameters are set using the _snapshot API they can be exposed as plain text by users able to query the _snapshot API.Enginsight
Vendor | Product | Version |
---|---|---|
elastic | elasticsearch | 6.0.0 ≤ 𝑥 ≤ 6.2.4 |
elastic | elasticsearch | 6.0.0:beta1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-200 - Exposure of Sensitive Information to an Unauthorized ActorThe product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
- CWE-311 - Missing Encryption of Sensitive DataThe software does not encrypt sensitive or critical information before storage or transmission.