Vulnerabilities > CVE-2023-31416 - Unspecified vulnerability in Elastic Cloud on Kubernetes 1.1.0
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
NONE Integrity impact
LOW Availability impact
NONE Summary
Secret token configuration is never applied when using ECK <2.8 with APM Server >=8.0. This could lead to anonymous requests to an APM Server being accepted and the data ingested into this APM deployment.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 2 |