Vulnerability Description
In Elasticsearch versions 6.0.0-beta1 to 6.2.4 a disclosure flaw was found in the _snapshot API. When the access_key and security_key parameters are set using the _snapshot API they can be exposed as plain text by users able to query the _snapshot API.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Elastic | Elasticsearch | >= 6.0.0, <= 6.2.4 |
Related Weaknesses (CWE)
References
- https://discuss.elastic.co/t/elastic-stack-6-3-0-and-5-6-10-security-update/1357Vendor Advisory
- https://www.elastic.co/community/securityVendor Advisory
- https://discuss.elastic.co/t/elastic-stack-6-3-0-and-5-6-10-security-update/1357Vendor Advisory
- https://www.elastic.co/community/securityVendor Advisory
FAQ
What is CVE-2018-3826?
CVE-2018-3826 is a vulnerability with a CVSS score of 6.5 (MEDIUM). In Elasticsearch versions 6.0.0-beta1 to 6.2.4 a disclosure flaw was found in the _snapshot API. When the access_key and security_key parameters are set using the _snapshot API they can be exposed as ...
How severe is CVE-2018-3826?
CVE-2018-3826 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-3826?
Check the references section above for vendor advisories and patch information. Affected products include: Elastic Elasticsearch.