ElasticsearchGHSA-5v8f-xx9m-wj44
Elasticsearch stores private key on disk unencrypted
Medium4.9CVE-2024-23444 · Published Jul 31, 2024 · updated Sep 10, 2026
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| org.elasticsearch:elasticsearch Maven | >= 8.0.0-alpha1, < 8.13.0 | 8.13.0 |
| < 7.17.23 | 7.17.23 |
Details and references
It was discovered by Elastic engineering that when elasticsearch-certutil CLI tool is used with the csr option in order to create a new Certificate Signing Requests, the associated private key that is generated is stored on disk unencrypted even if the `--pass` parameter is passed in the command invocation.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-311
- Also known as
- BIT-elasticsearch-2024-23444, CVE-2024-23444
- nvd.nist.gov/vuln/detail/CVE-2024-23444
- github.com/elastic/elasticsearch/pull/106105
- github.com/elastic/elasticsearch/pull/109834
- github.com/elastic/elasticsearch/commit/07296d596a1dee24730e33ad40b6726f70c6fc23
- github.com/elastic/elasticsearch/commit/321c4e1e6b738bf80faa41dbb9881489a4ab44e5
- github.com/elastic/elasticsearch/commit/bb1eddada3678257838b0590090ff9eb68acaa1b
- discuss.elastic.co/t/elasticsearch-8-13-0-7-17-23-security-update-esa-2024-12/364157
- github.com/elastic/elasticsearch
- security.netapp.com/advisory/ntap-20250404-0001
More Elasticsearch advisories
All Elasticsearch| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jul 262024 | Elasticsearch Insertion of Sensitive Information into Log File CVE-2023-49921Medium5.2fixed in 7.17.16, 8.11.2 | Medium5.2 | 7.17.16, 8.11.2 |
| Jun 132024 | Elasticsearch StackOverflow vulnerability CVE-2024-37280Medium4.9fixed in 8.14.0 | Medium4.9 | 8.14.0 |
| Mar 292024 | Elasticsearch Uncaught Exception leading to crash CVE-2024-23449Medium4.3fixed in 8.11.1 | Medium4.3 | 8.11.1 |
| Mar 272024 | Elasticsearch Incorrect Authorization vulnerability CVE-2024-23451Medium4.4fixed in 8.13.0 | Medium4.4 | 8.13.0 |
| Mar 272024 | Elasticsearch Uncontrolled Resource Consumption vulnerability CVE-2024-23450Medium4.9fixed in 7.17.19, 8.13.0 | Medium4.9 | 7.17.19, 8.13.0 |
| Dec 172024 | Elasticsearch Incorrect Authorization vulnerability CVE-2024-12539Mediumfixed in 8.16.2 | Medium | 8.16.2 |