Elastic Elasticsearch
cpe:2.3:a:elastic:elasticsearch:*:*:*:*:*:*:*
- ~7
- ~8.0.0, <= 8.19.7
- ~9.0.0, <= 9.1.7
- ~9.2.0, <= 9.2.1
A vulnerability exists in the PKI authentication realm of Elasticsearch, allowing for user impersonation through the use of specially crafted client certificates. This issue affects all versions of Elasticsearch 7.x, as well as versions 8.0.0 prior to 8.19.7 and versions 9.0.0 prior to 9.1.7 and 9.2.0 prior to 9.2.1. To exploit this vulnerability, a malicious actor must have a client certificate that is signed by a trusted Certificate Authority.
Exploitation of this vulnerability could lead to unauthorized user impersonation.
Users can upgrade to Elasticsearch versions 8.19.8, 9.1.8, or 9.2.2 to address this vulnerability. For those unable to upgrade, no workarounds are available.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.