CVE-2023-49923 – Enterprise Search Insertion of Sensitive Information into Log File
https://notcve.org/view.php?id=CVE-2023-49923
An issue was discovered by Elastic whereby the Documents API of App Search logged the raw contents of indexed documents at INFO log level. Depending on the contents of such documents, this could lead to the insertion of sensitive or private information in the App Search logs. Elastic has released 8.11.2 and 7.17.16 that resolves this issue by changing the log level at which these are logged to DEBUG, which is disabled by default. Elastic descubrió un problema por el cual la API de documentos de App Search registraba el contenido sin procesar de los documentos indexados en el nivel de registro INFO. Dependiendo del contenido de dichos documentos, esto podría dar lugar a la inserción de información confidencial o privada en los registros de búsqueda de aplicaciones. • https://discuss.elastic.co/t/enterprise-search-8-11-2-7-17-16-security-update-esa-2023-31/349181 https://www.elastic.co/community/security • CWE-532: Insertion of Sensitive Information into Log File •
CVE-2021-37940
https://notcve.org/view.php?id=CVE-2021-37940
An information disclosure via GET request server-side request forgery vulnerability was discovered with the Workplace Search Github Enterprise Server integration. Using this vulnerability, a malicious Workplace Search admin could use the GHES integration to view hosts that might not be publicly accessible. Se ha detectado una vulnerabilidad de divulgación de información por medio de una petición GET de tipo server-side request forgery con la integración de Workplace Search Github Enterprise Server. Usando esta vulnerabilidad, un administrador malicioso de Workplace Search podría usar la integración de GHES para visualizar hosts que podrían no ser de acceso público • https://discuss.elastic.co/t/enterprise-search-7-16-0-security-update/291146 • CWE-918: Server-Side Request Forgery (SSRF) •
CVE-2021-22148
https://notcve.org/view.php?id=CVE-2021-22148
Elastic Enterprise Search App Search versions before 7.14.0 was vulnerable to an issue where API keys were not bound to the same engines as their creator. This could lead to a less privileged user gaining access to unauthorized engines. Elastic Enterprise Search App Search versiones anteriores a 7.14.0, eran vulnerables a un problema por el que las claves API no estaban vinculadas a los mismos motores que su creador. Esto podía conllevar a que un usuario con menos privilegios obtuviera acceso a motores no autorizados • https://discuss.elastic.co/t/elastic-stack-7-14-0-security-update/280344 https://www.elastic.co/community/security • CWE-732: Incorrect Permission Assignment for Critical Resource •
CVE-2021-22149
https://notcve.org/view.php?id=CVE-2021-22149
Elastic Enterprise Search App Search versions before 7.14.0 are vulnerable to an issue where API keys were missing authorization via an alternate route. Using this vulnerability, an authenticated attacker could utilize API keys belonging to higher privileged users. Elastic Enterprise Search App Search versiones anteriores a 7.14.0, son vulnerables a un problema por el que faltaba la autorización de las claves API por medio de una ruta alternativa. Usando esta vulnerabilidad, un atacante autenticado podría utilizar claves de API pertenecientes a usuarios con mayores privilegios • https://discuss.elastic.co/t/elastic-stack-7-14-0-security-update/280344 https://www.elastic.co/community/security • CWE-732: Incorrect Permission Assignment for Critical Resource CWE-862: Missing Authorization •
CVE-2020-7018
https://notcve.org/view.php?id=CVE-2020-7018
Elastic Enterprise Search before 7.9.0 contain a credential exposure flaw in the App Search interface. If a user is given the �developer� role, they will be able to view the administrator API credentials. These credentials could allow the developer user to conduct operations with the same permissions of the App Search administrator. Elastic Enterprise Search versiones anteriores a 7.9.0, contiene un fallo de exposición de credenciales en la Interfaz App Search. Si a un usuario se le asigna el rol �developer�, podrá visualizar las credenciales de la API de administrador. • https://discuss.elastic.co/t/enterprise-search-7-9-0-security-update/245457 • CWE-266: Incorrect Privilege Assignment CWE-269: Improper Privilege Management •