Skip to content
ElasticsearchGHSA-pgq6-ccqj-hpqr

Elasticsearch privilege escalation

Medium4.3CVE-2022-23708 · Published Mar 4, 2022 · updated Feb 20, 2024

GitHub advisory

Affected versions

PackageAffectedFixed in
org.elasticsearch:elasticsearch
Maven
>= 7.16.0, < 7.17.17.17.1
Details and references

A flaw was discovered in Elasticsearch 7.17.0’s upgrade assistant, in which upgrading from version 6.x to 7.x would disable the in-built protections on the security index, allowing authenticated users with “*” index permissions access to this index. Users running a cluster on an affected version that had previously been upgraded from 6.x, should upgrade to 7.17.1. Users that are planning to upgrade from 6.x should not perform an upgrade from 6.x to versions 7.16 through 7.17.0 and should use 7.17.1+ for upgrades from 6.x.

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-269
Also known as
BIT-elasticsearch-2022-23708, CVE-2022-23708

More Elasticsearch advisories

All Elasticsearch
DateAdvisory
May 132022Improper Access Control in Elasticsearch
CVE-2019-7611High8.1fixed in 5.6.15, 6.6.1
May 132022Exposure of Sensitive Information to an Unauthorized Actor in Elasticsearch
CVE-2018-3831High8.8fixed in 5.6.12, 6.4.1
May 132022Elasticsearch subject to cross site scripting
CVE-2018-3824Medium6.1fixed in 5.6.9, 6.2.4
May 132022Improper Restriction of XML External Entity Reference in Elasticsearch
CVE-2018-17247Medium5.9fixed in 6.5.2
May 132022Exposure of Sensitive Information to an Unauthorized Actor in Elasticsearch
CVE-2018-17244Medium6.5fixed in 6.4.3
May 142022Improper Limitation of a Pathname to a Restricted Directory in Elasticsearch
CVE-2015-5531Mediumfixed in 1.6.1

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.