ElasticsearchGHSA-pgq6-ccqj-hpqr
Elasticsearch privilege escalation
Medium4.3CVE-2022-23708 · Published Mar 4, 2022 · updated Feb 20, 2024
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| org.elasticsearch:elasticsearch Maven | >= 7.16.0, < 7.17.1 | 7.17.1 |
Details and references
A flaw was discovered in Elasticsearch 7.17.0’s upgrade assistant, in which upgrading from version 6.x to 7.x would disable the in-built protections on the security index, allowing authenticated users with “*” index permissions access to this index. Users running a cluster on an affected version that had previously been upgraded from 6.x, should upgrade to 7.17.1. Users that are planning to upgrade from 6.x should not perform an upgrade from 6.x to versions 7.16 through 7.17.0 and should use 7.17.1+ for upgrades from 6.x.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-269
- Also known as
- BIT-elasticsearch-2022-23708, CVE-2022-23708
More Elasticsearch advisories
All Elasticsearch| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| May 132022 | Improper Access Control in Elasticsearch CVE-2019-7611High8.1fixed in 5.6.15, 6.6.1 | High8.1 | 5.6.15, 6.6.1 |
| May 132022 | Exposure of Sensitive Information to an Unauthorized Actor in Elasticsearch CVE-2018-3831High8.8fixed in 5.6.12, 6.4.1 | High8.8 | 5.6.12, 6.4.1 |
| May 132022 | Elasticsearch subject to cross site scripting CVE-2018-3824Medium6.1fixed in 5.6.9, 6.2.4 | Medium6.1 | 5.6.9, 6.2.4 |
| May 132022 | Improper Restriction of XML External Entity Reference in Elasticsearch CVE-2018-17247Medium5.9fixed in 6.5.2 | Medium5.9 | 6.5.2 |
| May 132022 | Exposure of Sensitive Information to an Unauthorized Actor in Elasticsearch CVE-2018-17244Medium6.5fixed in 6.4.3 | Medium6.5 | 6.4.3 |
| May 142022 | Improper Limitation of a Pathname to a Restricted Directory in Elasticsearch CVE-2015-5531Mediumfixed in 1.6.1 | Medium | 1.6.1 |