CVE-2024-23444

It was discovered by Elastic engineering that when elasticsearch-certutil CLI tool is used with the csr option in order to create a new Certificate Signing Requests, the associated private key that is generated is stored on disk unencrypted even if the --pass parameter is passed in the command invocation.
Configurations

No configuration.

History

01 Aug 2024, 12:42

Type Values Removed Values Added
Summary
  • (es) La ingeniería de Elastic descubrió que cuando se utiliza la herramienta CLI elasticsearch-certutil con la opción csr para crear nuevas solicitudes de firma de certificado, la clave privada asociada que se genera se almacena en el disco sin cifrar incluso si se pasa el parámetro --pass en la invocación del comando.

31 Jul 2024, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-07-31 18:15

Updated : 2024-08-01 12:42


NVD link : CVE-2024-23444

Mitre link : CVE-2024-23444

CVE.ORG link : CVE-2024-23444


JSON object : View

Products Affected

No product.

CWE
CWE-311

Missing Encryption of Sensitive Data