PT-2023-30151 · Elastic · Fleet Server
CVE-2023-46667
·
Publicado
2023-10-25
·
Atualizado
2023-11-03
CVSS v3.1
8.1
Alta
| Vetor | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Fleet Server versions 8.10.0 through 8.10.2
Description
An issue was discovered where Agent enrolment tokens are being inserted into the Fleet Server’s log file in plain text. These enrolment tokens could allow someone to enrol an agent into an agent policy, and potentially use that to retrieve other secrets in the policy including for Elasticsearch and third-party services. Alternatively, a threat actor could potentially enrol agents to the clusters and send arbitrary events to Elasticsearch.
Recommendations
For Fleet Server versions 8.10.0 through 8.10.2, consider disabling the logging of Agent enrolment tokens until a patch is available. Restrict access to the Fleet Server’s log file to minimize the risk of exploitation. Avoid using the affected versions until a fixed version is released. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Insertion into Log File
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Fleet Server