CVE-2023-46669Sensitive Information Exposure in Agent AND Elastic Defend

Severity
7.1HIGHNVD
CNA6.2
EPSS
0.1%
top 75.95%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 1

Description

Exposure of sensitive information to local unauthorized actors in Elastic Agent and Elastic Security Endpoint can lead to loss of confidentiality and impersonation of Endpoint to the Elastic Stack. This issue was identified by Elastic engineers and Elastic has no indication that it is known or has been exploited by malicious actors.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:NExploitability: 1.8 | Impact: 5.2

Affected Packages3 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-xr86-xwvg-mq5q: Exposure of sensitive information to local unauthorized actors in Elastic Agent and Elastic Security Endpoint can lead to loss of confidentiality and2025-05-01
CVEList
Elastic Agent / Elastic Endpoint Security local API key disclosure2025-05-01
CVE-2023-46669 — Sensitive Information Exposure | cvebase