Elastic Cloud on Kubernetes (ECK) secret token configuration issue
CVE-2023-31416
5.3MEDIUM
What is CVE-2023-31416?
Secret token configuration is never applied when using ECK <2.8 with APM Server >=8.0. This could lead to anonymous requests to an APM Server being accepted and the data ingested into this APM deployment.
Affected Version(s)
Elastic Cloud on Kubernetes <2.8