An issue was identified in Kibana where a user without access to Fleet can view Elastic Agent policies that could contain sensitive information. The nature of the sensitive information depends on the integrations enabled for the Elastic Agent and their respective versions.
{
"cwe_ids": [
"CWE-200"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/43xxx/CVE-2024-43707.json",
"cna_assigner": "elastic",
"unresolved_ranges": [
{
"extracted_events": [
{
"introduced": "8.0.0"
},
{
"fixed": "8.15.0"
}
],
"source": "AFFECTED_FIELD"
}
]
}"2026-08-12T15:15:29Z"
[
{
"id": "CVE-2024-43707-8673e70a",
"deprecated": false,
"signature_type": "Function",
"signature_version": "v1",
"digest": {
"length": 271.0,
"function_hash": "142192629617725741299022729598204077325"
},
"source": "https://github.com/elastic/elasticsearch/commit/1a77947f34deddb41af25e6f0ddb8e830159c179",
"target": {
"function": "createThreadPool",
"file": "x-pack/plugin/security/src/test/java/org/elasticsearch/xpack/security/authc/ApiKeyServiceTests.java"
}
},
{
"id": "CVE-2024-43707-9c9105ba",
"deprecated": false,
"signature_type": "Line",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"90979555117259467445263826000722655414",
"233880512092644159509098133445422903781",
"201588729648204699044316536751211233144",
"150381386453785713982991137249591284441"
]
},
"source": "https://github.com/elastic/elasticsearch/commit/1a77947f34deddb41af25e6f0ddb8e830159c179",
"target": {
"file": "x-pack/plugin/security/src/main/java/org/elasticsearch/xpack/security/authc/ApiKeyService.java"
}
},
{
"id": "CVE-2024-43707-cae71c55",
"deprecated": false,
"signature_type": "Function",
"signature_version": "v1",
"digest": {
"length": 2537.0,
"function_hash": "137023518409038292133452283468593548723"
},
"source": "https://github.com/elastic/elasticsearch/commit/1a77947f34deddb41af25e6f0ddb8e830159c179",
"target": {
"function": "validateApiKeyCredentials",
"file": "x-pack/plugin/security/src/main/java/org/elasticsearch/xpack/security/authc/ApiKeyService.java"
}
},
{
"id": "CVE-2024-43707-fbf59ae4",
"deprecated": false,
"signature_type": "Line",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"203603482067859804637258967793063382345",
"322917609237158501780418561654099552269",
"256253239670756748785358014200135771045",
"315837561795991804971382438615044649236",
"146427732354523605064218080296921708373",
"173231181477074759296592300368901057611",
"61022203414500058386117304455448959197",
"193300915082347298917541114706348147175",
"258077855627316307519262695880736716066",
"125996974648388146940214377483342596447",
"40188819877500306413169533609100026446",
"97819836589033936183410863291812511956",
"28174937397667876549461977660517314954",
"135344447971163041939327739838227678862",
"339252469867217754068016957649395888437"
]
},
"source": "https://github.com/elastic/elasticsearch/commit/1a77947f34deddb41af25e6f0ddb8e830159c179",
"target": {
"file": "x-pack/plugin/security/src/test/java/org/elasticsearch/xpack/security/authc/ApiKeyServiceTests.java"
}
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-43707.json"