Elastic Stack 6.3.0 and 5.6.10 Security Update


#1

Elasticsearch Information Exposure Vulnerability (ESA-2018-10)
In Elasticsearch versions 6.0.0-beta1 to 6.2.4 a disclosure flaw was found in the _snapshot API. When the access_key and security_key parameters are set using the _snapshot API they can be exposed as plain text by users able to query the _snapshot API.

Although it is advised in the 6.X _snapshot API documentation to define the access_key and security_key parameters in the keystore, it is still possible to define them outside of the keystore using the API.

Affected Versions: Elasticsearch versions 6.0.0-beta1 to 6.2.4

Solutions and Mitigations:
All users of Elasticsearch should upgrade to version 6.3.0. This update will prevent the _snapshot API from returning the access_key and security_key parameters in plain text.

CVE ID: CVE-2018-3826


Elasticsearch Information Exposure Vulnerability (ESA-2018-11)
A sensitive data disclosure flaw was found in the Elasticsearch repository-azure (formerly elasticsearch-cloud-azure) plugin. When the repository-azure plugin is set to log at TRACE level Azure credentials can be inadvertently logged.

Affected Versions:
All versions of Elasticsearch

Solutions and Mitigations:
All users of Elasticsearch should upgrade to version 6.3.0. This update will prevent the repository-azure plugin to expose Azure credentials in Elasticsearch logs.

CVE ID: CVE-2018-3827