Loading HuntDB...

GHSA-9fgp-xgx7-gpx6

GitHub Security Advisory

⚠ Unreviewed MODERATE Has CVE

Advisory Details

A flaw was discovered in ECE before 3.4.0 that might lead to the disclosure of sensitive information such as user passwords and Elasticsearch keystore settings values in logs such as the audit log or deployment logs in the Logging and Monitoring cluster. The affected APIs are PATCH /api/v1/user and PATCH /deployments/{deployment_id}/elasticsearch/{ref_id}/keystore

Related CVEs

Key Information

GHSA ID
GHSA-9fgp-xgx7-gpx6
Published
August 26, 2022 12:03 AM
Last Modified
September 1, 2022 12:00 AM
CVSS Score
5.0 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: September 4, 2025 6:33 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.