Medium severity5.3NVD Advisory· Published Oct 26, 2023· Updated Jun 17, 2026
CVE-2023-31416
CVE-2023-31416
Description
Secret token configuration is never applied when using ECK <2.8 with APM Server >=8.0. This could lead to anonymous requests to an APM Server being accepted and the data ingested into this APM deployment.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4cpe:2.3:a:elastic:elastic_cloud_on_kubernetes:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:elastic:elastic_cloud_on_kubernetes:*:*:*:*:*:*:*:*range: <2.8
- (no CPE)range: <2.8
- Range: >=8.0
Patches
Vulnerability mechanics
References
2- discuss.elastic.co/t/elastic-cloud-on-kubernetes-eck-2-8-security-update/343854nvdVendor Advisory
- www.elastic.co/community/securitynvdNot Applicable
News mentions
0No linked articles in our index yet.