CVE-2024-23444
31.07.2024, 18:15
It was discovered by Elastic engineering that when elasticsearch-certutil CLI tool is used with the csr option in order to create a new Certificate Signing Requests, the associated private key that is generated is stored on disk unencrypted even if the --pass parameter is passed in the command invocation.Enginsight
| Vendor | Product | Version |
|---|---|---|
| elastic | elasticsearch | 7.0.0 ≤ 𝑥 < 7.17.23 |
| elastic | elasticsearch | 8.0.0 ≤ 𝑥 < 8.13.0 |
𝑥
= Vulnerable software versions
Ubuntu Releases
Common Weakness Enumeration