CVE-2023-31417
Last modified
CVE-2023-31417 is a medium-severity vulnerability rated 4.4/10 on the CVSS scale. Elasticsearch generally filters out sensitive information and credentials before logging to the audit log. It was found that this filtering was not applied when requests to Elasticsearch use certain deprecated URIs for APIs. EPSS estimates a 0.23% chance of exploitation in the next 30 days.
Description
Elasticsearch generally filters out sensitive information and credentials before logging to the audit log. It was found that this filtering was not applied when requests to Elasticsearch use certain deprecated URIs for APIs. The impact of this flaw is that sensitive information such as passwords and tokens might be printed in cleartext in Elasticsearch audit logs. Note that audit logging is disabled by default and needs to be explicitly enabled and even when audit logging is enabled, request bodies that could contain sensitive information are not printed to the audit log unless explicitly configured.
Metrics
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Elastic | Elasticsearch | >= 7.0.0, <= 7.17.12 |
| Elastic | Elasticsearch | >= 8.0.0, <= 8.9.1 |
References
- https://security.netapp.com/advisory/ntap-20231130-0006/Third Party Advisory
- https://www.elastic.co/community/securityVendor Advisory
- https://security.netapp.com/advisory/ntap-20231130-0006/Third Party Advisory
- https://www.elastic.co/community/securityVendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-31417?
How severe is CVE-2023-31417?
How do I fix CVE-2023-31417?
Are you affected by CVE-2023-31417?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
