CVE-2024-23445

CVSS 3.1 Score 6.5 of 10 (medium)

Details

Published Jun 12, 2024
Updated: Jun 13, 2024

Summary

CVE-2024-23445: Elasticsearch's cross-cluster API keys allow search restrictions for a specific index when creating them. However, if the same key is used to grant replication for the same index, the search restrictions are ignored during cross-cluster search operations. This vulnerability only affects the API key based security model for remote clusters, which was previously a beta feature and is now released as GA with Elasticsearch 8.14.0. Unauthorized access to indexed data is a potential risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share