Weak Random Number Generator in Elastic Cloud on Kubernetes by Elastic
CVE-2020-7010
7.5HIGH
What is CVE-2020-7010?
Prior to version 1.1.0, Elastic Cloud on Kubernetes (ECK) employs a weak random number generator for password creation. This flaw can be exploited by an attacker who knows when the Elastic Stack cluster was deployed, significantly increasing the likelihood of successfully brute-forcing the Elasticsearch credentials generated during the deployment process.
Affected Version(s)
Elastic Cloud on Kubernetes before 1.1.0