{"id":"CVE-2024-23444","summary":"Elasticsearch elasticsearch-certutil csr fails to encrypt private key","details":"It was discovered by Elastic engineering that when elasticsearch-certutil CLI tool is used with the csr option in order to create a new Certificate Signing Requests, the associated private key that is generated is stored on disk unencrypted even if the --pass parameter is passed in the command invocation.","aliases":["BIT-elasticsearch-2024-23444","GHSA-5v8f-xx9m-wj44"],"modified":"2026-08-12T15:15:01.089555Z","published":"2024-07-31T17:26:12.784Z","related":["CGA-7hrw-x473-8q8j"],"database_specific":{"cna_assigner":"elastic","cwe_ids":["CWE-311"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/23xxx/CVE-2024-23444.json","unresolved_ranges":[{"extracted_events":[{"introduced":"7.x"},{"fixed":"7.17.23"},{"introduced":"8.x"},{"fixed":"8.13.0"}],"source":"AFFECTED_FIELD"}]},"references":[{"type":"WEB","url":"https://discuss.elastic.co/t/elasticsearch-8-13-0-7-17-23-security-update-esa-2024-12/364157"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/23xxx/CVE-2024-23444.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-23444"},{"type":"ADVISORY","url":"https://security.netapp.com/advisory/ntap-20250404-0001/"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/elastic/elasticsearch","events":[{"introduced":"b7e28a7232616c7a21bc879a535d801b8553ba77"},{"fixed":"61d76462eecaf09ada684d1b5d319b5ff6865a83"},{"introduced":"1b6a7ece17463df5ff54a3e1302d825889aa1161"},{"fixed":"09df99393193b2c53d92899662a8b8b3c55b45cd"}],"database_specific":{"cpe":"cpe:2.3:a:elastic:elasticsearch:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"7.0.0"},{"fixed":"7.17.23"},{"introduced":"8.0.0"},{"fixed":"8.13.0"}],"source":"CPE_RANGE"}}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-23444.json","vanir_signatures_modified":"2026-08-12T15:15:01Z","vanir_signatures":[{"id":"CVE-2024-23444-3fa86dc6","signature_type":"Function","signature_version":"v1","source":"https://github.com/elastic/elasticsearch/commit/61d76462eecaf09ada684d1b5d319b5ff6865a83","target":{"file":"qa/os/src/test/java/org/elasticsearch/packaging/test/DockerTests.java","function":"test600Interrupt"},"deprecated":false,"digest":{"function_hash":"69844453905830246677820397096534298013","length":935}},{"signature_type":"Line","signature_version":"v1","source":"https://github.com/elastic/elasticsearch/commit/09df99393193b2c53d92899662a8b8b3c55b45cd","target":{"file":"server/src/test/java/org/elasticsearch/threadpool/ThreadPoolTests.java"},"deprecated":false,"digest":{"threshold":0.9,"line_hashes":["36530912574437381226782567206995626327","244108005552100167940772669739727799311","122676380888478570388070130641794056358"]},"id":"CVE-2024-23444-9616b188"},{"deprecated":false,"digest":{"line_hashes":["268439700297186282373755313812072452487","26797522030344409565822344236984547088","49674375891833826585064844018322645796","241861009769944274883436754269135918658","110241150124042836880806124194125742521","4974205076996931494879974579405987532"],"threshold":0.9},"id":"CVE-2024-23444-bda6ba2f","signature_type":"Line","signature_version":"v1","source":"https://github.com/elastic/elasticsearch/commit/61d76462eecaf09ada684d1b5d319b5ff6865a83","target":{"file":"qa/os/src/test/java/org/elasticsearch/packaging/test/DockerTests.java"}}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N"}]}