CVE-2018-3831

Description

Elasticsearch Alerting and Monitoring in versions before 6.4.1 or 5.6.12 have an information disclosure issue when secrets are configured via the API. The Elasticsearch _cluster/settings API, when queried, could leak sensitive configuration information such as passwords, tokens, or usernames. This could allow an authenticated Elasticsearch user to improperly view these details.

Risk Information

Base Score
8.8
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
0.861

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2018-3831 are fixed in Elasticsearch Core 5.6.12Windows
Vulnerabilities CVE-2018-3831 are fixed in Elasticsearch Core 6.4.1Windows
Vulnerabilities CVE-2018-3831 are fixed in Elasticsearch Core for Linux 5.6.12Linux
Vulnerabilities CVE-2018-3831 are fixed in Elasticsearch Core for Linux 6.4.1Linux
Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2018-3831)NCM

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234