cbcvebase.
CVE-2023-31421
published 2023-10-26

CVE-2023-31421: It was discovered that when acting as TLS clients, Beats, Elastic Agent, APM Server, and Fleet Server did not verify whether the server certificate is valid…

PriorityP339high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
0.27%
18.6th percentile
It was discovered that when acting as TLS clients, Beats, Elastic Agent, APM Server, and Fleet Server did not verify whether the server certificate is valid for the target IP address; however, certificate signature validation is still performed. More specifically, when the client is configured to connect to an IP address (instead of a hostname) it does not validate the server certificate's IP SAN values against that IP address and certificate validation fails, and therefore the connection is not blocked as expected.

Affected

8 ranges
VendorProductVersion rangeFixed in
elasticapm_server
elasticapm_server8.0.0 – 8.9.2
elasticbeats
elasticelastic_agent
elasticelastic_agent8.0.0 – 8.9.2
elasticelastic_beats8.0.0 – 8.9.2
elasticelastic_fleet_server8.0.0 – 8.9.2
elasticfleet_server
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.