CVE-2023-46667 HIGH

CVE-2023-46667: Fleet Server Insertion of Sensitive Information into Log File

Vendor Elastic
Product Fleet Server
Weakness CWE-532 · Sensitive info in logs
Published October 26, 2023
Last update September 9, 2024

CVSS base score

8.1/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

What the vulnerability does

01Description

An issue was discovered in Fleet Server >= v8.10.0 and < v8.10.3 where Agent enrolment tokens are being inserted into the Fleet Server’s log file in plain text. These enrolment tokens could allow someone to enrol an agent into an agent policy, and potentially use that to retrieve other secrets in the policy including for Elasticsearch and third-party services. Alternatively a threat actor could potentially enrol agents to the clusters and send arbitrary events to Elasticsearch.

Key dates

02Disclosure timeline

October 26, 2023 CVE published
September 9, 2024 Record updated