VDB
Sign up
MEDIUM6.8

GHSA-m9gh-789g-q5pv

Elasticsearch PKI Realm Authentication Bypass Vulnerability Allows User Impersonation Through Crafted Client Certificates

Quick fix

GHSA-m9gh-789g-q5pv — org.elasticsearch.plugin:x-pack-security: upgrade to the fixed version with the command below.

# pom.xml: bump <version>8.19.8</version> for org.elasticsearch.plugin:x-pack-security

Details

Improper Authentication in Elasticsearch PKI realm can lead to user impersonation via specially crafted client certificates. A malicious actor would need to have such a crafted client certificate signed by a legitimate, trusted Certificate Authority.

Are you affected?

Enter the version of the package you're using.

Affected packages

Maven/org.elasticsearch.plugin:x-pack-security
Introduced in: 7.0.0-alpha1Fixed in: 8.19.8
Fix# pom.xml: bump <version>8.19.8</version> for org.elasticsearch.plugin:x-pack-security
Maven/org.elasticsearch.plugin:x-pack-security
Introduced in: 9.0.0-beta1Fixed in: 9.1.8
Fix# pom.xml: bump <version>9.1.8</version> for org.elasticsearch.plugin:x-pack-security
Maven/org.elasticsearch.plugin:x-pack-security
Introduced in: 9.2.0Fixed in: 9.2.2
Fix# pom.xml: bump <version>9.2.2</version> for org.elasticsearch.plugin:x-pack-security
Maven/org.elasticsearch.plugin:x-pack-core
Introduced in: 7.0.0-alpha1Fixed in: 8.19.8
Fix# pom.xml: bump <version>8.19.8</version> for org.elasticsearch.plugin:x-pack-core
Maven/org.elasticsearch.plugin:x-pack-core
Introduced in: 9.0.0-beta1Fixed in: 9.1.8
Fix# pom.xml: bump <version>9.1.8</version> for org.elasticsearch.plugin:x-pack-core
Maven/org.elasticsearch.plugin:x-pack-core
Introduced in: 9.2.0Fixed in: 9.2.2
Fix# pom.xml: bump <version>9.2.2</version> for org.elasticsearch.plugin:x-pack-core

References