Lucene search

K
redhatcveRedhat.comRH:CVE-2018-3831
HistorySep 24, 2018 - 8:50 p.m.

CVE-2018-3831

2018-09-2420:50:41
redhat.com
access.redhat.com
12

0.001 Low

EPSS

Percentile

34.0%

Elasticsearch Alerting and Monitoring in versions before 6.4.1 or 5.6.12 have an information disclosure issue when secrets are configured via the API. The Elasticsearch _cluster/settings API, when queried, could leak sensitive configuration information such as passwords, tokens, or usernames. This could allow an authenticated Elasticsearch user to improperly view these details.