Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:44067
HistoryOct 31, 2023 - 6:49 a.m.

Sensitive Information Disclosure

2023-10-3106:49:12
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
95
elasticsearch
vulnerability
sensitive information
disclosure
audit log
deprecated uris

CVSS3

4.4

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

AI Score

6.7

Confidence

Low

EPSS

0

Percentile

15.5%

org.elasticsearch: elasticsearch is vulnerable to Insertion Of Sensitive Information Into Log File. The vulnerability is caused by a failure to filter out sensitive information and credentials before logging to the audit log when requests to Elasticsearch use certain deprecated URIs for APIs. This can lead to sensitive information such as passwords and tokens getting printed in cleartext to Elasticsearch audit logs.

CVSS3

4.4

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

AI Score

6.7

Confidence

Low

EPSS

0

Percentile

15.5%