Vulnerability Description
It was discovered by Elastic engineering that when elasticsearch-certutil CLI tool is used with the csr option in order to create a new Certificate Signing Requests, the associated private key that is generated is stored on disk unencrypted even if the --pass parameter is passed in the command invocation.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Elastic | Elasticsearch | >= 7.0.0, < 7.17.23 |
Related Weaknesses (CWE)
References
- https://discuss.elastic.co/t/elasticsearch-8-13-0-7-17-23-security-update-esa-20Vendor Advisory
- https://security.netapp.com/advisory/ntap-20250404-0001/
FAQ
What is CVE-2024-23444?
CVE-2024-23444 is a vulnerability with a CVSS score of 4.9 (MEDIUM). It was discovered by Elastic engineering that when elasticsearch-certutil CLI tool is used with the csr option in order to create a new Certificate Signing Requests, the associated private key that is...
How severe is CVE-2024-23444?
CVE-2024-23444 has been rated MEDIUM with a CVSS base score of 4.9/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-23444?
Check the references section above for vendor advisories and patch information. Affected products include: Elastic Elasticsearch.