Secret token configuration is never applied when using ECK <2.8 with APM Server >=8.0. This could lead to anonymous requests to an APM Server being accepted and the data ingested into this APM deployment.
2023-10-26T19:15:45.270
2024-11-21T08:01:49.107
Modified
CVSSv3.1: 5.3 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | elastic | elastic_cloud_on_kubernetes | < 2.8 | Yes |
Application | elastic | apm_server | ≥ 8.0.0 | No |