U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Vulnerability Change Records for CVE-2024-23451

Change History

New CVE Received by NIST 3/27/2024 2:15:10 PM

Action Type Old Value New Value
Added CVSS V3.1

								
							
							
						
Elastic AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N
Added CWE

								
							
							
						
Elastic CWE-863
Added Description

								
							
							
						
Incorrect Authorization issue exists in the API key based security model for Remote Cluster Security, which is currently in Beta, in Elasticsearch 8.10.0 and before 8.13.0. This allows a malicious user with a valid API key for a remote cluster configured to use the new Remote Cluster Security to read arbitrary documents from any index on the remote cluster, and only if they use the Elasticsearch custom transport protocol to issue requests with the target index ID, the shard ID and the document ID. None of Elasticsearch REST API endpoints are affected by this issue.
Added Reference

								
							
							
						
Elastic https://discuss.elastic.co/t/elasticsearch-8-13-0-security-update-esa-2024-07/356315 [No types assigned]