{"id":"CVE-2024-23444","aliases":["BIT-elasticsearch-2024-23444","GHSA-5v8f-xx9m-wj44"],"url":"https://o3.security/vulnerability/CVE-2024-23444","summary":"Elasticsearch elasticsearch-certutil csr fails to encrypt private key","details":"It was discovered by Elastic engineering that when elasticsearch-certutil CLI tool is used with the csr option in order to create a new Certificate Signing Requests, the associated private key that is generated is stored on disk unencrypted even if the --pass parameter is passed in the command invocation.","published":"2024-07-31T17:26:12.784Z","modified":"2026-08-12T15:15:01.089555Z","cvss":{"score":4.9,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"org.elasticsearch:elasticsearch","fixedVersion":"8.13.0"},{"ecosystem":"Maven","name":"org.elasticsearch:elasticsearch","fixedVersion":"7.17.23"}],"fix":{"url":"https://github.com/elastic/elasticsearch/pull/106105","label":"elastic/elasticsearch#106105"},"references":[{"type":"WEB","url":"https://discuss.elastic.co/t/elasticsearch-8-13-0-7-17-23-security-update-esa-2024-12/364157"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/23xxx/CVE-2024-23444.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-23444"},{"type":"ADVISORY","url":"https://security.netapp.com/advisory/ntap-20250404-0001/"},{"type":"WEB","url":"https://github.com/elastic/elasticsearch/pull/106105"},{"type":"WEB","url":"https://github.com/elastic/elasticsearch/pull/109834"},{"type":"WEB","url":"https://github.com/elastic/elasticsearch/commit/07296d596a1dee24730e33ad40b6726f70c6fc23"},{"type":"WEB","url":"https://github.com/elastic/elasticsearch/commit/321c4e1e6b738bf80faa41dbb9881489a4ab44e5"},{"type":"WEB","url":"https://github.com/elastic/elasticsearch/commit/bb1eddada3678257838b0590090ff9eb68acaa1b"},{"type":"PACKAGE","url":"https://github.com/elastic/elasticsearch"},{"type":"WEB","url":"https://security.netapp.com/advisory/ntap-20250404-0001"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T15:15:01.089555Z"}}