CVE-2022-23708
03.03.2022, 22:15
A flaw was discovered in Elasticsearch 7.17.0s upgrade assistant, in which upgrading from version 6.x to 7.x would disable the in-built protections on the security index, allowing authenticated users with * index permissions access to this index.Enginsight
Vendor | Product | Version |
---|---|---|
elastic | elasticsearch | 7.16.0 ≤ 𝑥 < 7.17.1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration