CVE Database
/

CVE-2022-23708

Back to search

CVE-2022-23708

Published: Mar 3, 2022

Modified: Aug 3, 2024

PUBLISHED

Description

A flaw was discovered in Elasticsearch 7.17.0’s upgrade assistant, in which upgrading from version 6.x to 7.x would disable the in-built protections on the security index, allowing authenticated users with “*” index permissions access to this index.

VendorProductVersions

Elastic

elasticsearch

affected
Versions 7.16.0 through 7.17.0

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now