CVE-2023-31421

Source
https://cve.org/CVERecord?id=CVE-2023-31421
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-31421.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2023-31421
Published
2023-10-26T03:10:52.684Z
Modified
2026-08-12T03:51:26.893116540Z
Severity
  • 5.9 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
Beats, Elastic Agent, APM Server, and Fleet Server Improper Certificate Validation issue
Details

It was discovered that when acting as TLS clients, Beats, Elastic Agent, APM Server, and Fleet Server did not verify whether the server certificate is valid for the target IP address; however, certificate signature validation is still performed. More specifically, when the client is configured to connect to an IP address (instead of a hostname) it does not validate the server certificate's IP SAN values against that IP address and certificate validation fails, and therefore the connection is not blocked as expected.

Database specific
{
    "cwe_ids": [
        "CWE-295"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/31xxx/CVE-2023-31421.json",
    "cna_assigner": "elastic",
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "introduced": "8.0.0, 8.9.2"
                },
                {
                    "last_affected": "8.0.0, 8.9.2"
                },
                {
                    "introduced": "8.0.0, 8.9.2"
                },
                {
                    "last_affected": "8.0.0, 8.9.2"
                },
                {
                    "introduced": "8.0.0, 8.9.2"
                },
                {
                    "last_affected": "8.0.0, 8.9.2"
                },
                {
                    "introduced": "8.0.0, 8.9.2"
                },
                {
                    "last_affected": "8.0.0, 8.9.2"
                }
            ],
            "source": "AFFECTED_FIELD"
        }
    ]
}
References

Affected packages

Git / github.com/elastic/apm-server

Affected ranges

Type
GIT
Repo
https://github.com/elastic/apm-server
Events
Database specific
Show details
{
    "cpe": "cpe:2.3:a:elastic:apm_server:*:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "8.0.0"
        },
        {
            "last_affected": "8.9.2"
        }
    ],
    "source": "CPE_RANGE"
}

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-31421.json"

Git / github.com/elastic/elastic-agent

Affected ranges

Type
GIT
Repo
https://github.com/elastic/elastic-agent
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Database specific
Show details
{
    "cpe": "cpe:2.3:a:elastic:elastic_agent:*:*:*:*:*:*:*:*",
    "source": "CPE_RANGE",
    "extracted_events": [
        {
            "introduced": "8.0.0"
        },
        {
            "last_affected": "8.9.2"
        }
    ]
}

Affected versions

v8.*
v8.9.0
v8.9.1
v8.9.2

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-31421.json"