Cleartext storage of sensitive information in Elasticsearch - CVE-2024-23444

 

Cleartext storage of sensitive information in Elasticsearch - CVE-2024-23444

Published: August 1, 2024


Vulnerability identifier: #VU95145
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-23444
CWE-ID: CWE-312
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to gain access to sensitive information.

The vulnerability exists within the new Certificate Signing Requests when elasticsearch-certutil CLI tool is used with the csr option in order to create a new request. The associated private key that is generated is stored on disk unencrypted even if the --pass parameter is passed in the command invocation. A local user with access to the system can obtain the key.


Affected software

Elasticsearch
IBM Cloud Pak for Watson AIOps
Watson CP4D Data Stores
watsonx Assistant Cartridge
watsonx Orchestrate with watsonx Assistant Cartridge - Assistant Builder Component
IBM Watson Discovery for IBM Cloud Pak for Data
IBM Watson Assistant for IBM Cloud Pak for Data
IBM Observability with Instana
watsonx.data
IBM Security SOAR

How to mitigate CVE-2024-23444

Install updates from vendor's website.

Elasticsearch - addressed in versions 7.17.23, 8.13.0
IBM Cloud Pak for Watson AIOps - update to 4.10.0
IBM Watson Discovery for IBM Cloud Pak for Data - update to 5.3.1
watsonx.data - update to 2.1
IBM Watson Assistant for IBM Cloud Pak for Data - update to 5.1
Watson CP4D Data Stores - update to 5.1
watsonx Assistant Cartridge - update to 5.1.1
watsonx Orchestrate with watsonx Assistant Cartridge - Assistant Builder Component - update to 5.1.1
IBM Security SOAR - update to 51.0.4.0
IBM Observability with Instana - update to 285

External References

Related Security Bulletins