Beveiligingsadvies

CVE-2025-37731

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2025-12-15 10:42:21
Laatst bijgewerkt 2026-02-26 16:07:40
Toegewezen door elastic
CVSS-score 6.8
Status PUBLISHED

Beschrijving

Improper Authentication in Elasticsearch PKI realm can lead to user impersonation via specially crafted client certificates. A malicious actor would need to have such a crafted client certificate signed by a legitimate, trusted Certificate Authority.