Overview
About vulnerability
Improper Authentication in Elasticsearch PKI realm can lead to user impersonation via specially crafted client certificates. A malicious actor would need to have such a crafted client certificate signed by a legitimate, trusted Certificate Authority.Details
- Affected product:
- Elasticsearch , Spring , elasticsearch , wildfly
- Affected packages:
- aggs-matrix-stats-client @ 7.9.3 (+1038 more)