Database/Control plane, storage & DevOps
Elasticsearch: elasticsearch-certutil --csr writes the private key to disk unencrypted despite --pass
CVSS 4.9CVE-2024-23444Control plane, storage & DevOpscurated
Impact
elasticsearch-certutil --csr writes the private key to disk unencrypted despite --pass
Who can reach it
Network (remote)
What to do
Control-plane: upgrade + reissue any cert whose key was generated this way
References
Related entries
- Elasticsearch: Crafted _search query stringCVE-2023-31419 · ElasticsearchMedium
- Linux perf/x86/amd - race between amd_pmu_enable_all, perf NMI and throttling: A race between AMD PMU enablementCVE-2022-49781 · Linux perf/x86/amd - race between amd_pmu_enable_all, perf NMI and throttlingMedium
- Intel Neural Compressor (TOCTOU): A time-of-check/time-of-use race in Neural Compressor lets an authenticated localCVE-2024-21792 · Intel Neural Compressor (TOCTOU)Medium
- GitLab: stored XSS via pasted HTML in the Content EditorCVE-2026-19619 · GitLab CE/EE (Content Editor, pasted HTML sanitization)Medium
- Rittal CMC III cabinet lock / access-card system: The access cards used to open control cabinets secured with RittalCVE-2022-40633 · Rittal CMC III cabinet lock / access-card systemMedium
- Keycloak: Redirect scheme filtering bypassed by appending a wildcardCVE-2023-6134 · KeycloakMedium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.