Bug 2066385 (CVE-2022-23708) - CVE-2022-23708 elasticsearch: privilege escalation vulnerability (ESA-2022-02)
Summary: CVE-2022-23708 elasticsearch: privilege escalation vulnerability (ESA-2022-02)
Keywords:
Status: NEW
Alias: CVE-2022-23708
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Nobody
QA Contact:
URL:
Whiteboard:
Depends On: 2072284 2072285 2072293 2072294 2072295 2074217
Blocks: 2066389
TreeView+ depends on / blocked
 
Reported: 2022-03-21 16:11 UTC by Patrick Del Bello
Modified: 2024-03-14 17:27 UTC (History)
43 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description Patrick Del Bello 2022-03-21 16:11:26 UTC
A flaw was discovered in Elasticsearch 7.17.0’s upgrade assistant, in which upgrading from version 6.x to 7.x would disable the in-built protections on the security index, allowing authenticated users with “*” index permissions access to this index.

https://discuss.elastic.co/t/elastic-stack-7-17-1-security-update/298447

Comment 3 Anten Skrabec 2022-04-05 23:08:37 UTC
Created python-elasticsearch tracking bugs for this issue:

Affects: epel-all [bug 2072294]
Affects: fedora-all [bug 2072295]
Affects: openstack-rdo [bug 2072293]


Note You need to log in before you can comment on or make changes to this bug.