Uploaded image for project: 'Policy Framework'
  1. Policy Framework
  2. POLICY-1538

Upgrade Elasticsearch to 6.4.x to clear security issue

XMLWordPrintable

      Elasticsearch Alerting and Monitoring in versions before 6.4.1 or 5.6.12 have an information disclosure issue when secrets are configured via the API. The Elasticsearch _cluster/settings API, when queried, could leak sensitive configuration information such as passwords, tokens, or usernames. This could allow an authenticated Elasticsearch user to improperly view these details.

      The recommendation is to upgrade.

      There is another security issues with 6.4.1 - recommend to upgrade to 6.4.3

            pdragosh pdragosh
            pdragosh pdragosh
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

              Created:
              Updated:
              Resolved: