PT-2023-30151 · Elastic · Fleet Server

CVE-2023-46667

·

Publicado

2023-10-25

·

Atualizado

2023-11-03

CVSS v3.1

8.1

Alta

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Fleet Server versions 8.10.0 through 8.10.2
Description An issue was discovered where Agent enrolment tokens are being inserted into the Fleet Server’s log file in plain text. These enrolment tokens could allow someone to enrol an agent into an agent policy, and potentially use that to retrieve other secrets in the policy including for Elasticsearch and third-party services. Alternatively, a threat actor could potentially enrol agents to the clusters and send arbitrary events to Elasticsearch.
Recommendations For Fleet Server versions 8.10.0 through 8.10.2, consider disabling the logging of Agent enrolment tokens until a patch is available. Restrict access to the Fleet Server’s log file to minimize the risk of exploitation. Avoid using the affected versions until a fixed version is released. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Insertion into Log File

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-46667

Produtos afetados

Fleet Server