CVE-2023-46668: Elastic Endpoint Insertion of Sensitive Information into Log File
If Elastic Endpoint (v7.9.0 - v8.10.3) is configured to use a non-default option in which the logging level is explicitly set to debug, and when Elastic Agent is simultaneously configured to collect and send those logs to Elasticsearch, then Elastic Agent API keys can be viewed in Elasticsearch in plaintext. These API keys could be used to write arbitrary data and read Elastic Endpoint user artifacts.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this issue?
The vulnerability ID is CVE-2023-46668.
What is the title of this vulnerability?
The title of this vulnerability is 'Elastic Endpoint Insertion of Sensitive Information into Log File'.
What is the severity level of CVE-2023-46668?
The severity level of CVE-2023-46668 is critical.
Which version of Elastic Endpoint is affected by this vulnerability?
Elastic Endpoint versions 7.9.0 to 8.10.3 are affected by this vulnerability.
How can the Elastic Agent API keys be viewed in Elasticsearch due to this vulnerability?
If Elastic Endpoint is configured to use a non-default option where the logging level is set to debug and Elastic Agent is configured to collect and send logs to Elasticsearch, the Elastic Agent API keys can be viewed in Elasticsearch.