====================================================================== CERT-Renater Note d'Information No. 2024/VULN316 _____________________________________________________________________ DATE : 04/07/2024 HARDWARE PLATFORM(S): / OPERATING SYSTEM(S): Systems running Elastic Cloud Enterprise versions from 3.0.0 and prior to 3.7.2. ===================================================================== https://discuss.elastic.co/t/elastic-cloud-enterprise-3-7-2-security-update-esa-2024-18/362181 _____________________________________________________________________ Elastic Cloud Enterprise 3.7.2 Security Update (ESA-2024-18) Announcements Security Announcements ikakavas (Ioannis Kakavas) June 28, 2024, 4:54am 1 ECE Improper Authorization (ESA-2024-18) It was identified that under certain specific preconditions, an API key that was originally created with a specific privileges could be subsequently used to create new API keys that have elevated privileges. Affected Versions: ECE versions after 3.0.0 and before 3.7.2 Solutions and Mitigations: Users should upgrade to version 3.7.2. Severity: CVSSv3: 8.1(High) - CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H CVE ID: CVE-2024-37282 ========================================================= + CERT-RENATER | tel : 01-53-94-20-44 + + 23/25 Rue Daviel | fax : 01-53-94-20-41 + + 75013 Paris | email:cert@support.renater.fr + =========================================================