CVE-2018-3831
Severity CVSS v4.0:
Pending analysis
Type:
CWE-200
Information Leak / Disclosure
Publication date:
19/09/2018
Last modified:
07/04/2020
Description
Elasticsearch Alerting and Monitoring in versions before 6.4.1 or 5.6.12 have an information disclosure issue when secrets are configured via the API. The Elasticsearch _cluster/settings API, when queried, could leak sensitive configuration information such as passwords, tokens, or usernames. This could allow an authenticated Elasticsearch user to improperly view these details.
Impact
Base Score 3.x
8.80
Severity 3.x
HIGH
Base Score 2.0
4.00
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:elastic:elasticsearch:*:*:*:*:*:*:*:* | 5.6.0 (including) | 5.6.12 (excluding) |
| cpe:2.3:a:elastic:elasticsearch:*:*:*:*:*:*:*:* | 6.0.0 (including) | 6.4.1 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



