SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2018-3825

If an attacker can connect to ZooKeeper directly they would be able to access configuration information of other tenants if their cluster ID is known.

MEDIUM 5.9EPSS 0.65%

Does this matter?

Lower severity and a low EPSS score (0.65%). Track it; it rarely justifies an emergency change on its own.

Description

In Elastic Cloud Enterprise (ECE) versions prior to 1.1.4 a default master encryption key is used in the process of granting ZooKeeper access to Elasticsearch clusters. Unless explicitly overwritten, this master key is predictable across all ECE deployments. If an attacker can connect to ZooKeeper directly they would be able to access configuration information of other tenants if their cluster ID is known.

CVSS 3.0
5.9 MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS
0.65% probability · 49th percentile
CISA KEV
Not listed
Weakness
CWE-321, CWE-1188
Affected
elastic/elastic cloud enterprise
Source
security@elastic.co

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.