Vulnerability GHSA-m9gh-789g-q5pv
Medium Risk
MEDIUM RISK
CVSS Score: 6.8
Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
9 months ago
December 15, 2025 at 12:30 PM UTC
Elasticsearch PKI Realm Authentication Bypass Vulnerability Allows User Impersonation Through Crafted Client Certificates
7.8.1 and 7.12.0 - 8.0.1 and 8.7.0 - 8.7.1 and 9.2.0 - 9.2.1
7.8.1 and 7.12.0 - 8.0.1 and 8.7.0 - 8.7.1 and 9.2.0 - 9.2.1
Summary
Elasticsearch PKI Realm Authentication Bypass Vulnerability Allows User Impersonation Through Crafted Client Certificates
Details
Improper Authentication in Elasticsearch PKI realm can lead to user impersonation via specially crafted client certificates. A malicious actor would need to have such a crafted client certificate signed by a legitimate, trusted Certificate Authority.
Related Vulnerabilities
Other vulnerabilities affecting the same packages
Medium Risk
9 months ago
Elasticsearch privileged authenticated users can cause DoS through Excessive Resource Allocation
7.8.1 and 7.12.0 - 8.0.1 and 8.7.0 - 8.7.1 and 9.2.0 - 9.2.1 GHSA-gphj-4h6p-37xq
7.8.1 and 7.12.0 - 8.0.1 and 8.7.0 - 8.7.1 and 9.2.0 - 9.2.1 GHSA-gphj-4h6p-37xq
Medium Risk
9 months ago
Elasticsearch has Excessive Allocation of Resources via Submission of Oversized User Settings Data
7.8.1 and 7.12.0 - 8.0.1 and 8.7.0 - 8.7.1 GHSA-qf7c-7r9h-mm92
7.8.1 and 7.12.0 - 8.0.1 and 8.7.0 - 8.7.1 GHSA-qf7c-7r9h-mm92
Impacted packages
Timeline
Published
9 months ago
December 15, 2025 at 12:30 PM UTC
Fixed (8.19.8)
Unknown
Unknown
Fixed (9.1.8)
Unknown
Unknown
Fixed (9.2.2)
Unknown
Unknown
Fixed (8.19.8)
Unknown
Unknown
Fixed (9.1.8)
Unknown
Unknown
Fixed (9.2.2)
Unknown
Unknown
Last Modified
2 days ago
September 25, 2026 at 05:45 PM UTC