CVE-2024-23444
31.07.2024, 18:15
It was discovered by Elastic engineering that when elasticsearch-certutil CLI tool is used with the csr option in order to create a new Certificate Signing Requests, the associated private key that is generated is stored on disk unencrypted even if the --pass parameter is passed in the command invocation.Enginsight
Vendor | Product | Version |
---|---|---|
elastic | elasticsearch | 7.0.0 ≤ 𝑥 < 7.17.23 |
elastic | elasticsearch | 8.0.0 ≤ 𝑥 < 8.13.0 |
𝑥
= Vulnerable software versions

Ubuntu Releases
Common Weakness Enumeration