Skip to content
ElasticsearchGHSA-5v8f-xx9m-wj44

Elasticsearch stores private key on disk unencrypted

Medium4.9CVE-2024-23444 · Published Jul 31, 2024 · updated Sep 10, 2026

GitHub advisory

Affected versions

PackageAffectedFixed in
org.elasticsearch:elasticsearch
Maven
>= 8.0.0-alpha1, < 8.13.08.13.0
< 7.17.237.17.23
Details and references

It was discovered by Elastic engineering that when elasticsearch-certutil CLI tool is used with the csr option in order to create a new Certificate Signing Requests, the associated private key that is generated is stored on disk unencrypted even if the `--pass` parameter is passed in the command invocation.

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-311
Also known as
BIT-elasticsearch-2024-23444, CVE-2024-23444

More Elasticsearch advisories

All Elasticsearch
DateAdvisory
Jul 262024Elasticsearch Insertion of Sensitive Information into Log File
CVE-2023-49921Medium5.2fixed in 7.17.16, 8.11.2
Jun 132024Elasticsearch StackOverflow vulnerability
CVE-2024-37280Medium4.9fixed in 8.14.0
Mar 292024Elasticsearch Uncaught Exception leading to crash
CVE-2024-23449Medium4.3fixed in 8.11.1
Mar 272024Elasticsearch Incorrect Authorization vulnerability
CVE-2024-23451Medium4.4fixed in 8.13.0
Mar 272024Elasticsearch Uncontrolled Resource Consumption vulnerability
CVE-2024-23450Medium4.9fixed in 7.17.19, 8.13.0
Dec 172024Elasticsearch Incorrect Authorization vulnerability
CVE-2024-12539Mediumfixed in 8.16.2

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.