Fleet Server Insertion of Sensitive Information into Log File
CVE-2023-46667
What is CVE-2023-46667?
An identified security issue in Fleet Server versions 8.10.0 to 8.10.2 has been found where sensitive enrolment tokens are logged in plain text. This exposure can enable unauthorized individuals to enroll agents into managing policies, potentially allowing them to access sensitive information stored within those policies, such as Elasticsearch and various third-party service secrets. Additionally, it poses a risk of malicious agents being able to relay bogus events back to Elasticsearch, thereby undermining the integrity and reliability of the data.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Fleet Server 8.10.0 < 8.10.3
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved