CVE-2018-3831

CVE-2018-3831

Elasticsearch Alerting and Monitoring in versions before 6.4.1 or 5.6.12 have an information disclosure issue when secrets are configured via the API. The Elasticsearch _cluster/settings API, when queried, could leak sensitive configuration information such as passwords, tokens, or usernames. This could allow an authenticated Elasticsearch user to improperly view these details.

Source: CVE-2018-3831

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다