{"id":"CVE-2022-23708","details":"A flaw was discovered in Elasticsearch 7.17.0’s upgrade assistant, in which upgrading from version 6.x to 7.x would disable the in-built protections on the security index, allowing authenticated users with “*” index permissions access to this index.","aliases":["BIT-elasticsearch-2022-23708","GHSA-pgq6-ccqj-hpqr"],"modified":"2026-08-12T13:00:26.462041Z","published":"2022-03-03T21:48:14Z","database_specific":{"cna_assigner":"elastic","cwe_ids":["CWE-264"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/23xxx/CVE-2022-23708.json"},"references":[{"type":"WEB","url":"https://discuss.elastic.co/t/elastic-stack-7-17-1-security-update/298447"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/23xxx/CVE-2022-23708.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-23708"},{"type":"ADVISORY","url":"https://security.netapp.com/advisory/ntap-20220729-0003/"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/elastic/elasticsearch","events":[{"introduced":"6fc81662312141fe7691d7c1c91b8658ac17aa0d"},{"fixed":"e5acb99f822233d62d6444ce45a4543dc1c8059a"}],"database_specific":{"extracted_events":[{"introduced":"7.16.0"},{"fixed":"7.17.1"}],"source":"CPE_RANGE","cpe":"cpe:2.3:a:elastic:elasticsearch:*:*:*:*:*:*:*:*"}}],"versions":["v7.17.0","v7.16.1","v7.16.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-23708.json","vanir_signatures_modified":"2026-08-12T13:00:26Z","vanir_signatures":[{"deprecated":false,"digest":{"line_hashes":["236836815310709596383608286106644790881","196381633559554339088896249561089112903","146873537089190934299820367594122268218","334357347513489300173246355664845051067"],"threshold":0.9},"id":"CVE-2022-23708-46868c56","signature_type":"Line","signature_version":"v1","source":"https://github.com/elastic/elasticsearch/commit/e5acb99f822233d62d6444ce45a4543dc1c8059a","target":{"file":"x-pack/plugin/deprecation/src/test/java/org/elasticsearch/xpack/deprecation/NodeDeprecationChecksTests.java"}},{"source":"https://github.com/elastic/elasticsearch/commit/e5acb99f822233d62d6444ce45a4543dc1c8059a","target":{"file":"x-pack/plugin/deprecation/src/test/java/org/elasticsearch/xpack/deprecation/NodeDeprecationChecksTests.java","function":"monitoringExporterGroupedSetting"},"deprecated":false,"digest":{"function_hash":"165482351688345707173695098433441287823","length":1319},"id":"CVE-2022-23708-5d0e65b7","signature_type":"Function","signature_version":"v1"},{"deprecated":false,"digest":{"function_hash":"81242662974819149104372912973832414697","length":1971},"id":"CVE-2022-23708-6a9a5cc6","signature_type":"Function","signature_version":"v1","source":"https://github.com/elastic/elasticsearch/commit/e5acb99f822233d62d6444ce45a4543dc1c8059a","target":{"file":"x-pack/plugin/deprecation/src/main/java/org/elasticsearch/xpack/deprecation/NodeDeprecationChecks.java","function":"deprecatedAffixGroupedSetting"}},{"target":{"file":"x-pack/plugin/deprecation/src/main/java/org/elasticsearch/xpack/deprecation/NodeDeprecationChecks.java"},"deprecated":false,"digest":{"line_hashes":["142965958877837107677794816119383469250","16841893402362179998478465353024513221","206022478088870697769046647787008760564","216095244516550820119455808353224037846","46142714263656663437914612207197745209","15088390182960363056546331595655444257","234182045088025048292414092125412433047","255272807197668761160103392865329307400","117362707116158116788652207123491886620","292421547288413531568142709484731301692","304976113980423471330374207259607813425"],"threshold":0.9},"id":"CVE-2022-23708-7138c559","signature_type":"Line","signature_version":"v1","source":"https://github.com/elastic/elasticsearch/commit/e5acb99f822233d62d6444ce45a4543dc1c8059a"},{"target":{"file":"x-pack/plugin/deprecation/src/main/java/org/elasticsearch/xpack/deprecation/NodeDeprecationChecks.java","function":"deprecatedAffixSetting"},"deprecated":false,"digest":{"function_hash":"1789796353482668074025554634844605557","length":1194},"id":"CVE-2022-23708-7b0c41ec","signature_type":"Function","signature_version":"v1","source":"https://github.com/elastic/elasticsearch/commit/e5acb99f822233d62d6444ce45a4543dc1c8059a"}]}}],"schema_version":"1.9.0"}