Exposure of sensitive information to local unauthorized actors in Elastic Agent and Elastic Security Endpoint can lead to loss of confidentiality and impersonation of Endpoint to the Elastic Stack. This issue was identified by Elastic engineers and Elastic has no indication that it is known or has been exploited by malicious actors.
History

Thu, 01 May 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 01 May 2025 13:15:00 +0000

Type Values Removed Values Added
Description Exposure of sensitive information to local unauthorized actors in Elastic Agent and Elastic Security Endpoint can lead to loss of confidentiality and impersonation of Endpoint to the Elastic Stack. This issue was identified by Elastic engineers and Elastic has no indication that it is known or has been exploited by malicious actors.
Title Elastic Agent / Elastic Endpoint Security local API key disclosure
Weaknesses CWE-200
References
Metrics cvssV3_1

{'score': 6.2, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: elastic

Published: 2025-05-01T12:59:49.101Z

Updated: 2025-05-01T15:33:08.751Z

Reserved: 2023-10-24T17:28:32.185Z

Link: CVE-2023-46669

cve-icon Vulnrichment

Updated: 2025-05-01T14:51:51.851Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-05-01T13:15:49.000

Modified: 2025-05-02T13:53:20.943

Link: CVE-2023-46669

cve-icon Redhat

No data.