Unencrypted Private Keys Generated by elasticsearch-certutil CLI Tool
CVE-2024-23444
7.5HIGH
What is CVE-2024-23444?
A security flaw was identified in the elasticsearch-certutil CLI tool, specifically when utilizing the csr option to generate new Certificate Signing Requests. The vulnerability arises as the corresponding private key is saved unencrypted on disk, exposing it to potential unauthorized access, even in cases where the --pass parameter is included in the command. This oversight may lead to unauthorized use of sensitive data, posing significant risks to security.
Affected Version(s)
Elasticsearch 7.x < 7.17.23
Elasticsearch 8.x < 8.13.0