Elastic Fleet Server vulnerabilities

3 known vulnerabilities affecting elastic/fleet_server.

Total CVEs
3
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH2

Vulnerabilities

Page 1 of 1
CVE-2024-52975CRITICALCVSS 9.0≥ 8.13.0, < 8.15.02025-01-23
CVE-2024-52975 [CRITICAL] CWE-200 CVE-2024-52975: An issue was identified in Fleet Server where Fleet policies that could contain sensitive informatio An issue was identified in Fleet Server where Fleet policies that could contain sensitive information were logged on INFO and ERROR log levels. The nature of the sensitive information largely depends on the integrations enabled.
cvelistv5nvd
CVE-2023-31421HIGHCVSS 7.5v8.0.0, 8.9.22023-10-26
CVE-2023-31421 [HIGH] CWE-295 CVE-2023-31421: It was discovered that when acting as TLS clients, Beats, Elastic Agent, APM Server, and Fleet Serve It was discovered that when acting as TLS clients, Beats, Elastic Agent, APM Server, and Fleet Server did not verify whether the server certificate is valid for the target IP address; however, certificate signature validation is still performed. More specifically, when the client is configured to connect to an IP address (instead of a hostname) it doe
cvelistv5nvd
CVE-2023-46667HIGHCVSS 8.1≥ 8.10.0, < 8.10.32023-10-26
CVE-2023-46667 [HIGH] CWE-532 CVE-2023-46667: An issue was discovered in Fleet Server >= v8.10.0 and < v8.10.3 where Agent enrolment tokens are be An issue was discovered in Fleet Server >= v8.10.0 and < v8.10.3 where Agent enrolment tokens are being inserted into the Fleet Server’s log file in plain text. These enrolment tokens could allow someone to enrol an agent into an agent policy, and potentially use that to retrieve other secrets in the policy including for Elasticsearch and third-party
cvelistv5nvd