VYPR
Medium severity6.5NVD Advisory· Published Sep 19, 2018· Updated Jun 17, 2026

CVE-2018-3826

CVE-2018-3826

Description

In Elasticsearch versions 6.0.0-beta1 to 6.2.4 a disclosure flaw was found in the _snapshot API. When the access_key and security_key parameters are set using the _snapshot API they can be exposed as plain text by users able to query the _snapshot API.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

4
  • cpe:2.3:a:elastic:elasticsearch:*:*:*:*:*:*:*:*+ 3 more
    • cpe:2.3:a:elastic:elasticsearch:*:*:*:*:*:*:*:*range: >=6.0.0,<=6.2.4
    • cpe:2.3:a:elastic:elasticsearch:6.0.0:beta1:*:*:*:*:*:*
    • (no CPE)range: >=6.0.0-beta1, <=6.2.4
    • (no CPE)range: 6.0.0-beta1 to 6.2.4

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.