Bug 2066385 (CVE-2022-23708)

Summary: CVE-2022-23708 elasticsearch: privilege escalation vulnerability (ESA-2022-02)
Product: [Other] Security Response Reporter: Patrick Del Bello <pdelbell>
Component: vulnerabilityAssignee: Nobody <nobody>
Status: NEW --- QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: aileenc, alazarot, anstephe, aos-bugs, apevec, apevec, bmontgom, chazlett, dbruno, eglynn, emingora, eparis, ewolinet, fjansen, gmalinko, ibek, janstey, jburrell, jcantril, jjoyce, jochrist, jokerman, jrokos, jwendell, jwon, kverlaen, lhh, mburns, mmagr, mnovotny, nstielau, pantinor, pdelbell, piotr1212, pjindal, rcernich, rfreiman, rguimara, sponnaga, spower, steve.traylen, twalsh, vkumar
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: If docs needed, set a value
Doc Text:
A flaw was found in the upgrade assistant for Elasticsearch. When upgrading from version 6.x to 7.x, the built-in protections on the security index are disabled, allowing authenticated users to access the index.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2072284, 2072285, 2072293, 2072294, 2072295, 2074217    
Bug Blocks: 2066389    

Description Patrick Del Bello 2022-03-21 16:11:26 UTC
A flaw was discovered in Elasticsearch 7.17.0’s upgrade assistant, in which upgrading from version 6.x to 7.x would disable the in-built protections on the security index, allowing authenticated users with “*” index permissions access to this index.

https://discuss.elastic.co/t/elastic-stack-7-17-1-security-update/298447

Comment 3 Anten Skrabec 2022-04-05 23:08:37 UTC
Created python-elasticsearch tracking bugs for this issue:

Affects: epel-all [bug 2072294]
Affects: fedora-all [bug 2072295]
Affects: openstack-rdo [bug 2072293]