Medium severity4.4NVD Advisory· Published Mar 27, 2024· Updated Jun 17, 2026
CVE-2024-23451
CVE-2024-23451
Description
Incorrect Authorization issue exists in the API key based security model for Remote Cluster Security, which is currently in Beta, in Elasticsearch 8.10.0 and before 8.13.0. This allows a malicious user with a valid API key for a remote cluster configured to use the new Remote Cluster Security to read arbitrary documents from any index on the remote cluster, and only if they use the Elasticsearch custom transport protocol to issue requests with the target index ID, the shard ID and the document ID. None of Elasticsearch REST API endpoints are affected by this issue.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.elasticsearch:elasticsearchMaven | >= 8.10.0, < 8.13.0 | 8.13.0 |
Affected products
9cpe:2.3:a:elastic:elasticsearch:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:elastic:elasticsearch:*:*:*:*:*:*:*:*range: >=8.10.0,<8.13.0
- (no CPE)range: 8.10.0
- ghsa-coords7 versionspkg:maven/org.elasticsearch/elasticsearchpkg:apk/chainguard/elasticsearch-8pkg:apk/chainguard/elasticsearch-8-bitnamipkg:apk/chainguard/elasticsearch-8-configpkg:apk/chainguard/elasticsearch-8-iamguardedpkg:apk/chainguard/elasticsearch-configpkg:bitnami/elasticsearch
>= 8.10.0, < 8.13.0+ 6 more
- (no CPE)range: >= 8.10.0, < 8.13.0
- (no CPE)range: < 8.13.1-r0
- (no CPE)range: < 8.13.1-r0
- (no CPE)range: < 8.13.1-r0
- (no CPE)range: < 8.13.1-r0
- (no CPE)range: < 8.13.1-r0
- (no CPE)range: >= 8.10.0, < 8.13.0
Patches
Vulnerability mechanics
References
3- discuss.elastic.co/t/elasticsearch-8-13-0-security-update-esa-2024-07/356315nvdVendor AdvisoryWEB
- github.com/advisories/GHSA-r3hx-qfh5-r9m7ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2024-23451ghsaADVISORY
News mentions
0No linked articles in our index yet.