CVE Database
/

CVE-2018-3831

Back to search

CVE-2018-3831

Published: Sep 19, 2018

Modified: Aug 5, 2024

PUBLISHED

Description

Elasticsearch Alerting and Monitoring in versions before 6.4.1 or 5.6.12 have an information disclosure issue when secrets are configured via the API. The Elasticsearch _cluster/settings API, when queried, could leak sensitive configuration information such as passwords, tokens, or usernames. This could allow an authenticated Elasticsearch user to improperly view these details.

VendorProductVersions

Elastic

Elasticsearch

affected
before 5.6.12 and 6.4.1

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now