First published: Thu Mar 03 2022(Updated: )
A flaw was discovered in Elasticsearch 7.17.0’s upgrade assistant, in which upgrading from version 6.x to 7.x would disable the in-built protections on the security index, allowing authenticated users with “*” index permissions access to this index.
Credit: bressers@elastic.co
Affected Software | Affected Version | How to fix |
---|---|---|
Elastic Elasticsearch | >=7.16.0<7.17.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-23708 is a vulnerability discovered in Elasticsearch 7.17.0's upgrade assistant that disables security protections on the security index during an upgrade from version 6.x to 7.x.
CVE-2022-23708 affects Elasticsearch 7.17.0 by allowing authenticated users with "*" index permissions to access the security index, which is usually protected.
CVE-2022-23708 has a severity value of 4.3, which is classified as medium.
To fix CVE-2022-23708, upgrade Elasticsearch to version 7.17.1 or later.
More information about CVE-2022-23708 can be found at the following references: [1](https://discuss.elastic.co/t/elastic-stack-7-17-1-security-update/298447) [2](https://security.netapp.com/advisory/ntap-20220729-0003/)