SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2023-46667

These enrolment tokens could allow someone to enrol an agent into an agent policy, and potentially use that to retrieve other secrets in the policy including for Elasticsearch and third-party services.

HIGH 8.1EPSS 0.55%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (0.55%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

An issue was discovered in Fleet Server >= v8.10.0 and < v8.10.3 where Agent enrolment tokens are being inserted into the Fleet Server’s log file in plain text. These enrolment tokens could allow someone to enrol an agent into an agent policy, and potentially use that to retrieve other secrets in the policy including for Elasticsearch and third-party services. Alternatively a threat actor could potentially enrol agents to the clusters and send arbitrary events to Elasticsearch.

CVSS 3.1
8.1 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
EPSS
0.55% probability · 44th percentile
CISA KEV
Not listed
Weakness
CWE-532
Affected
elastic/fleet server
Source
security@elastic.co

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.