CVE-2022-23716: Medium severity elastic cloud enterprise vulnerability
Published Sep 28, 2022
·Updated
A flaw was discovered in ECE before 3.1.1 that could lead to the disclosure of the SAML signing private key used for the RBAC features, in deployment logs in the Logging and Monitoring cluster.
Affected Software
1 affected component
Elastic Cloud Enterprise<3.1.1
Event History
Sep 28, 2022
CVE Published
via MITRE·07:34 PM
Data Sourced
via MITRE·07:34 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this flaw?
The vulnerability ID of this flaw is CVE-2022-23716.
2
What software version is affected by this flaw?
ECE before version 3.1.1 is affected by this flaw.
3
What is the severity of CVE-2022-23716?
The severity of CVE-2022-23716 is medium with a CVSS score of 5.3.
4
What is the impact of this flaw?
This flaw could lead to the disclosure of the SAML signing private key used for the RBAC features.
5
How can I fix CVE-2022-23716?
You can fix CVE-2022-23716 by updating to ECE version 3.1.1 or higher.