CVE-2022-23716

Published Sep 28, 2022

Last updated 6 months ago

Overview

Description
A flaw was discovered in ECE before 3.1.1 that could lead to the disclosure of the SAML signing private key used for the RBAC features, in deployment logs in the Logging and Monitoring cluster.
Source
bressers@elastic.co
NVD status
Modified

Risk scores

CVSS 3.1

Type
Primary
Base score
5.3
Impact score
1.4
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Severity
MEDIUM

Weaknesses

bressers@elastic.co
CWE-532
nvd@nist.gov
CWE-532

Social media

Hype score
Not currently trending

Configurations