CVE-2023-31421
Last modified
CVE-2023-31421 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. It was discovered that when acting as TLS clients, Beats, Elastic Agent, APM Server, and Fleet Server did not verify whether the server certificate is valid for the target IP address; however, certificate signature validation is still performed. More specifically, when the client is configured to connect to an IP address (instead of a hostname) it does not validate the server certificate's IP SAN values against that IP address and certificate validation fails, and therefore the connection is not blocked as expected.. EPSS estimates a 0.27% chance of exploitation in the next 30 days.
Description
It was discovered that when acting as TLS clients, Beats, Elastic Agent, APM Server, and Fleet Server did not verify whether the server certificate is valid for the target IP address; however, certificate signature validation is still performed. More specifically, when the client is configured to connect to an IP address (instead of a hostname) it does not validate the server certificate's IP SAN values against that IP address and certificate validation fails, and therefore the connection is not blocked as expected.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Elastic | Elastic Beats | >= 8.0.0, <= 8.9.2 |
| Elastic | Elastic Agent | >= 8.0.0, <= 8.9.2 |
| Elastic | Apm Server | >= 8.0.0, <= 8.9.2 |
| Elastic | Elastic Fleet Server | >= 8.0.0, <= 8.9.2 |
References
- https://www.elastic.co/community/securityVendor Advisory
- https://www.elastic.co/community/securityVendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-31421?
How severe is CVE-2023-31421?
How do I fix CVE-2023-31421?
Are you affected by CVE-2023-31421?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
