Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
145615 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.148222
Categoría:Privilege escalation
Título:Elastic Elasticsearch Java Vulnerability (ESA-2022-06)
Resumen:Elastic Elasticsearch is prone to a vulnerability in Java.
Descripción:Summary:
Elastic Elasticsearch is prone to a vulnerability in Java.

Vulnerability Insight:
A vulnerability affecting the implementation of Elliptic Curve
Digital Signing Algorithm (ECDSA) based signatures verification in Java JDK versions 15 and later
was published on April 19, 2022. This vulnerability affects Oracle Java and OpenJDK, including
other JDKs derived from OpenJDK.

Affected Software/OS:
Elastic Elasticsearch version 6.8.x and 7.9.2 and later.

Solution:
Update to version 7.17.4, 8.2.1 or later.

CVSS Score:
5.0

CVSS Vector:
AV:N/AC:L/Au:N/C:N/I:P/A:N

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2022-21449
Debian Security Information: DSA-5128 (Google Search)
https://www.debian.org/security/2022/dsa-5128
Debian Security Information: DSA-5131 (Google Search)
https://www.debian.org/security/2022/dsa-5131
https://www.oracle.com/security-alerts/cpuapr2022.html
http://www.openwall.com/lists/oss-security/2022/04/28/2
http://www.openwall.com/lists/oss-security/2022/04/28/3
http://www.openwall.com/lists/oss-security/2022/04/28/4
http://www.openwall.com/lists/oss-security/2022/04/28/5
http://www.openwall.com/lists/oss-security/2022/04/28/6
http://www.openwall.com/lists/oss-security/2022/04/28/7
http://www.openwall.com/lists/oss-security/2022/04/29/1
http://www.openwall.com/lists/oss-security/2022/04/30/1
http://www.openwall.com/lists/oss-security/2022/04/30/2
http://www.openwall.com/lists/oss-security/2022/04/30/3
http://www.openwall.com/lists/oss-security/2022/04/30/4
http://www.openwall.com/lists/oss-security/2022/05/01/1
http://www.openwall.com/lists/oss-security/2022/05/01/2
http://www.openwall.com/lists/oss-security/2022/05/02/1
CopyrightCopyright (C) 2022 Greenbone Networks GmbH

Esta es sólo una de 145615 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.