CVE-2022-23716
5.3
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Exploitability: 3.9 / Impact: 1.4
Source: NVD
Description
A flaw was discovered in ECE before 3.1.1 that could lead to the disclosure of the SAML signing private key used for the RBAC features, in deployment logs in the Logging and Monitoring cluster.
Affected (1)
Products: Elastic: Elastic Cloud Enterprise
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.1.1 |
References (4)
Source: security@elastic.co
Release NotesVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Release NotesVendor Advisory
Timeline
No history available yet.