← voltar
CVE-2023-46667

Fleet Server Insertion of Sensitive Information into Log File

CVSS 8.1 HIGHEPSS 0.5%CWE-532
Vexday Risk Score
21Baixo
Decisão SSVC (CISA)
Track
Sem sinal de exploração → monitorar
CVSS 8.1EPSS 0.5%KEV nãoPoC Nuclei Metasploit Patch
Ciclo de vida
26 out 2023Publicada no NVD
Recomendação: Monitorar — sem sinal de exploração no momento.
An issue was discovered in Fleet Server >= v8.10.0 and < v8.10.3 where Agent enrolment tokens are being inserted into the Fleet Server’s log file in plain text. These enrolment tokens could allow someone to enrol an agent into an agent policy, and potentially use that to retrieve other secrets in the policy including for Elasticsearch and third-party services. Alternatively a threat actor could potentially enrol agents to the clusters and send arbitrary events to Elasticsearch.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Produtos afetados
Elastic · Fleet Server

Quer saber se a sua infraestrutura está exposta a isto?

Falar com a TrueHacking →