{"id":"GHSA-r9fv-qpm9-rj4g","summary":"Exposure of Sensitive Information to an Unauthorized Actor in Elasticsearch","details":"Elasticsearch Alerting and Monitoring in versions before 6.4.1 or 5.6.12 have an information disclosure issue when secrets are configured via the API. The Elasticsearch _cluster/settings API, when queried, could leak sensitive configuration information such as passwords, tokens, or usernames. This could allow an authenticated Elasticsearch user to improperly view these details.","aliases":["CVE-2018-3831"],"modified":"2023-11-01T04:49:30.606955Z","published":"2022-05-13T01:27:27Z","database_specific":{"nvd_published_at":"2018-09-19T19:29:00Z","cwe_ids":["CWE-200"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2022-06-28T23:46:58Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2018-3831"},{"type":"WEB","url":"https://discuss.elastic.co/t/elastic-stack-6-4-1-and-5-6-12-security-update/149035"},{"type":"WEB","url":"https://www.elastic.co/community/security"}],"affected":[{"package":{"name":"org.elasticsearch:elasticsearch","ecosystem":"Maven","purl":"pkg:maven/org.elasticsearch/elasticsearch"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"5.6.0"},{"fixed":"5.6.12"}]}],"versions":["5.6.0","5.6.1","5.6.10","5.6.11","5.6.2","5.6.3","5.6.4","5.6.5","5.6.6","5.6.7","5.6.8","5.6.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-r9fv-qpm9-rj4g/GHSA-r9fv-qpm9-rj4g.json"}},{"package":{"name":"org.elasticsearch:elasticsearch","ecosystem":"Maven","purl":"pkg:maven/org.elasticsearch/elasticsearch"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"6.0.0"},{"fixed":"6.4.1"}]}],"versions":["6.0.0","6.0.1","6.1.0","6.1.1","6.1.2","6.1.3","6.1.4","6.2.0","6.2.1","6.2.2","6.2.3","6.2.4","6.3.0","6.3.1","6.3.2","6.4.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-r9fv-qpm9-rj4g/GHSA-r9fv-qpm9-rj4g.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}