VDB
Sign up
MEDIUM4.9

GHSA-5v8f-xx9m-wj44

Elasticsearch stores private key on disk unencrypted

Quick fix

GHSA-5v8f-xx9m-wj44 — org.elasticsearch:elasticsearch: upgrade to the fixed version with the command below.

# pom.xml: bump <version>8.13.0</version> for org.elasticsearch:elasticsearch

Details

It was discovered by Elastic engineering that when elasticsearch-certutil CLI tool is used with the csr option in order to create a new Certificate Signing Requests, the associated private key that is generated is stored on disk unencrypted even if the `--pass` parameter is passed in the command invocation.

Are you affected?

Enter the version of the package you're using.

Affected packages

Maven/org.elasticsearch:elasticsearch
Introduced in: 8.0.0-alpha1Fixed in: 8.13.0
Fix# pom.xml: bump <version>8.13.0</version> for org.elasticsearch:elasticsearch
Maven/org.elasticsearch:elasticsearch
Introduced in: 0Fixed in: 7.17.23
Fix# pom.xml: bump <version>7.17.23</version> for org.elasticsearch:elasticsearch

References