{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-09-30T16:07:58.530","vulnerabilities":[{"cve":{"id":"CVE-2022-23716","sourceIdentifier":"security@elastic.co","published":"2022-09-28T20:15:11.307","lastModified":"2026-06-17T04:30:41.493","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A flaw was discovered in ECE before 3.1.1 that could lead to the disclosure of the SAML signing private key used for the RBAC features, in deployment logs in the Logging and Monitoring cluster."},{"lang":"es","value":"Se ha detectado un fallo en ECE versiones anteriores a 3.1.1, que podía conllevar a una revelación de la clave privada de firma de SAML usada para las funciones RBAC, en los registros de despliegue del clúster de registro y supervisión"}],"affected":[{"source":"security@elastic.co","affectedData":[{"vendor":"Elastic","product":"Elastic Cloud Enterprise","versions":[{"version":"Versions through 3.1.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-05-21T14:22:36.819713Z","id":"CVE-2022-23716","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security@elastic.co","type":"Secondary","description":[{"lang":"en","value":"CWE-532"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-532"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:elastic:elastic_cloud_enterprise:*:*:*:*:*:*:*:*","versionEndExcluding":"3.1.1","matchCriteriaId":"AB999B53-7191-465C-B5DF-CF033C23670B"}]}]}],"references":[{"url":"https://discuss.elastic.co/t/elastic-cloud-enterprise-3-1-1-security-update/315317","source":"security@elastic.co","tags":["Release Notes","Vendor Advisory"]},{"url":"https://www.elastic.co/community/security/","source":"security@elastic.co","tags":["Product"]},{"url":"https://discuss.elastic.co/t/elastic-cloud-enterprise-3-1-1-security-update/315317","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://www.elastic.co/community/security/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Product"]}]}}]}