CVE-2024-23445
CVSS 3.1 Score 6.5 of 10 (medium)
Details
Published Jun 12, 2024
Updated: Jun 13, 2024
Summary
CVE-2024-23445: Elasticsearch's cross-cluster API keys allow search restrictions for a specific index when creating them. However, if the same key is used to grant replication for the same index, the search restrictions are ignored during cross-cluster search operations. This vulnerability only affects the API key based security model for remote clusters, which was previously a beta feature and is now released as GA with Elasticsearch 8.14.0. Unauthorized access to indexed data is a potential risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Elasticsearch
Affected Vendors
- Elastic