2024-07-14 02:06:08 +00:00

99 lines
2.6 KiB
JSON

{
"id": "CVE-2022-23716",
"sourceIdentifier": "bressers@elastic.co",
"published": "2022-09-28T20:15:11.307",
"lastModified": "2022-09-30T18:14:44.783",
"vulnStatus": "Analyzed",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "A flaw was discovered in ECE before 3.1.1 that could lead to the disclosure of the SAML signing private key used for the RBAC features, in deployment logs in the Logging and Monitoring cluster."
},
{
"lang": "es",
"value": "Se ha detectado un fallo en ECE versiones anteriores a 3.1.1, que pod\u00eda conllevar a una revelaci\u00f3n de la clave privada de firma de SAML usada para las funciones RBAC, en los registros de despliegue del cl\u00faster de registro y supervisi\u00f3n"
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "NONE",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "LOW",
"integrityImpact": "NONE",
"availabilityImpact": "NONE",
"baseScore": 5.3,
"baseSeverity": "MEDIUM"
},
"exploitabilityScore": 3.9,
"impactScore": 1.4
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-532"
}
]
},
{
"source": "bressers@elastic.co",
"type": "Secondary",
"description": [
{
"lang": "en",
"value": "CWE-532"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:elastic:elastic_cloud_enterprise:*:*:*:*:*:*:*:*",
"versionEndExcluding": "3.1.1",
"matchCriteriaId": "AB999B53-7191-465C-B5DF-CF033C23670B"
}
]
}
]
}
],
"references": [
{
"url": "https://discuss.elastic.co/t/elastic-cloud-enterprise-3-1-1-security-update/315317",
"source": "bressers@elastic.co",
"tags": [
"Release Notes",
"Vendor Advisory"
]
},
{
"url": "https://www.elastic.co/community/security/",
"source": "bressers@elastic.co",
"tags": [
"Product"
]
}
]
}