Security Flaw in Elasticsearch Upgrade Assistant Disabling Protections
CVE-2022-23708
4.3MEDIUM
What is CVE-2022-23708?
A security vulnerability has been identified in the upgrade assistant of Elasticsearch 7.17.0. During the upgrade process from version 6.x to 7.x, the built-in protections for the security index are inadvertently disabled. This flaw allows authenticated users with wildcard ('*') permissions on indices to gain unauthorized access to the sensitive security index, posing significant risks to data integrity and confidentiality.
Affected Version(s)
elasticsearch Versions 7.16.0 through 7.17.0