Red Hat Bugzilla – Bug 1632452
CVE-2018-3831 elasticsearch: Information exposure via _cluster/settings API
Last modified: 2018-10-12 03:06:10 EDT
Elasticsearch Alerting and Monitoring in versions before 6.4.1 or 5.6.12 have an information disclosure issue when secrets are configured via the API. The Elasticsearch _cluster/settings API, when queried, could leak sensitive configuration information such as passwords, tokens, or usernames. This could allow an authenticated Elasticsearch user to improperly view these details. References: https://discuss.elastic.co/t/elastic-stack-6-4-1-and-5-6-12-security-update/149035 https://www.elastic.co/community/security
Created elasticsearch tracking bugs for this issue: Affects: fedora-all [bug 1632454]
Created elasticsearch tracking bugs for this issue: Affects: fedora-all [bug 1632971]
OpenShift uses Search Guard [1] to protect the affected the _cluster/settings endpoint with certificate based authentication. Therefore none of the OpenShift 3.x versions are affected. [1] https://docs.search-guard.com/latest/index