Medium severity4.3NVD Advisory· Published Mar 3, 2022· Updated Jun 17, 2026
CVE-2022-23708
CVE-2022-23708
Description
A flaw was discovered in Elasticsearch 7.17.0’s upgrade assistant, in which upgrading from version 6.x to 7.x would disable the in-built protections on the security index, allowing authenticated users with “*” index permissions access to this index.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.elasticsearch:elasticsearchMaven | >= 7.16.0, < 7.17.1 | 7.17.1 |
Affected products
4Versions 7.16.0 through 7.17.0+ 1 more
- (no CPE)range: Versions 7.16.0 through 7.17.0
- cpe:2.3:a:elastic:elasticsearch:*:*:*:*:*:*:*:*range: >=7.16.0,<7.17.1
- ghsa-coords2 versions
>= 7.16.0, < 7.17.1+ 1 more
- (no CPE)range: >= 7.16.0, < 7.17.1
- (no CPE)range: >= 7.16.0, < 7.17.1
Patches
Vulnerability mechanics
References
5- discuss.elastic.co/t/elastic-stack-7-17-1-security-update/298447nvdVendor AdvisoryWEB
- github.com/advisories/GHSA-pgq6-ccqj-hpqrghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2022-23708ghsaADVISORY
- security.netapp.com/advisory/ntap-20220729-0003/nvdThird Party Advisory
- security.netapp.com/advisory/ntap-20220729-0003ghsaWEB
News mentions
0No linked articles in our index yet.