Related Vulnerabilities: CVE-2022-23708  

A flaw was discovered in Elasticsearch 7.17.0’s upgrade assistant, in which upgrading from version 6.x to 7.x would disable the in-built protections on the security index, allowing authenticated users with “*” index permissions access to this index.

Description

The MITRE CVE dictionary describes this issue as:

A flaw was discovered in Elasticsearch 7.17.0’s upgrade assistant, in which upgrading from version 6.x to 7.x would disable the in-built protections on the security index, allowing authenticated users with “*” index permissions access to this index.

Additional Information

  • Bugzilla 2066385: CVE-2022-23708 elasticsearch: privilege escalation vulnerability (ESA-2022-02)
  • CWE-273: Improper Check for Dropped Privileges
  • FAQ: Frequently asked questions about CVE-2022-23708