Vulnerability Details CVE-2022-23716
A flaw was discovered in ECE before 3.1.1 that could lead to the disclosure of the SAML signing private key used for the RBAC features, in deployment logs in the Logging and Monitoring cluster.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 52.3%
CVSS Severity
CVSS v3 Score 5.3
Products affected by CVE-2022-23716
-
cpe:2.3:a:elastic:elastic_cloud_enterprise:-
-
cpe:2.3:a:elastic:elastic_cloud_enterprise:1.0.0
-
cpe:2.3:a:elastic:elastic_cloud_enterprise:1.0.1
-
cpe:2.3:a:elastic:elastic_cloud_enterprise:1.0.2
-
cpe:2.3:a:elastic:elastic_cloud_enterprise:1.1.0
-
cpe:2.3:a:elastic:elastic_cloud_enterprise:1.1.1
-
cpe:2.3:a:elastic:elastic_cloud_enterprise:1.1.2
-
cpe:2.3:a:elastic:elastic_cloud_enterprise:1.1.3
-
cpe:2.3:a:elastic:elastic_cloud_enterprise:1.1.4
-
cpe:2.3:a:elastic:elastic_cloud_enterprise:1.1.5
-
cpe:2.3:a:elastic:elastic_cloud_enterprise:2.0.0
-
cpe:2.3:a:elastic:elastic_cloud_enterprise:2.0.1
-
cpe:2.3:a:elastic:elastic_cloud_enterprise:2.1.0
-
cpe:2.3:a:elastic:elastic_cloud_enterprise:2.1.1
-
cpe:2.3:a:elastic:elastic_cloud_enterprise:2.2.0
-
cpe:2.3:a:elastic:elastic_cloud_enterprise:2.2.1
-
cpe:2.3:a:elastic:elastic_cloud_enterprise:2.2.2
-
cpe:2.3:a:elastic:elastic_cloud_enterprise:2.2.3
-
cpe:2.3:a:elastic:elastic_cloud_enterprise:2.3.0
-
cpe:2.3:a:elastic:elastic_cloud_enterprise:2.3.1