NVD Vulnerability Detail
Search Exploit, PoC
CVE-2024-23444
Summary

It was discovered by Elastic engineering that when elasticsearch-certutil CLI tool is used with the csr option in order to create a new Certificate Signing Requests, the associated private key that is generated is stored on disk unencrypted even if the --pass parameter is passed in the command invocation.

Publication Date Aug. 1, 2024, 3:15 a.m.
Registration Date Aug. 1, 2024, 10 a.m.
Last Update Aug. 1, 2024, 9:42 p.m.
Related information, measures and tools
Common Vulnerabilities List