216.73.217.22

CVE-2025-37731

· Published 15/12/2025 11:15 · Modified 18/12/2025 01:49

Labels: CVE-2025-37731 2025-12-15CVE-2025-37731[email protected]

Essential information

Published
15/12/2025 11:15
Modified
18/12/2025 01:49
Author
Creator
CVSS
6.8 MEDIUM (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N

CVSS metrics

Description

Improper Authentication in Elasticsearch PKI realm can lead to user impersonation via specially crafted client certificates. A malicious actor would need to have such a crafted client certificate signed by a legitimate, trusted Certificate Authority.

NVD status

Status
Analyzed — CVE has had analysis completed and all data associations made.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
elastic / elasticsearch cpe:2.3:a:elastic:elasticsearch:*:*:*:*:*:*:*:*
elastic / elasticsearch cpe:2.3:a:elastic:elasticsearch:*:*:*:*:*:*:*:*
elastic / elasticsearch cpe:2.3:a:elastic:elasticsearch:*:*:*:*:*:*:*:*
elastic / elasticsearch cpe:2.3:a:elastic:elasticsearch:*:*:*:*:*:*:*:*

References