Elasticsearch elasticsearch-certutil csr fails to encrypt private key
Vulnerability Description
It was discovered by Elastic engineering that when elasticsearch-certutil CLI tool is used with the csr option in order to create a new Certificate Signing Requests, the associated private key that is generated is stored on disk unencrypted even if the --pass parameter is passed in the command invocation.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-23444
Credits & Attribution
No credits recorded in the NVD database.
References
More from Elastic
View All →Affected Vendor
Elastic
View all reports →