Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Elasticsearch Improper Authentication
Vulnerability Description
Improper Authentication in Elasticsearch PKI realm can lead to user impersonation via specially crafted client certificates. A malicious actor would need to have such a crafted client certificate signed by a legitimate, trusted Certificate Authority.
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
Vulnerability Type
认证机制不恰当
Vulnerability Title
Elasticsearch 安全漏洞
Vulnerability Description
Elasticsearch是荷兰Elastic公司的一个搜索分析引擎。 Elasticsearch存在安全漏洞,该漏洞源于认证不当,可能导致通过特制客户端证书进行用户冒充。
CVSS Information
N/A
Vulnerability Type
N/A