Elastic Network Drive Connector security update advisory (CVE-2024-23447)

Overview

An update has been made available to fix vulnerabilities in the Elastic Network Drive Connector. Users of affected versions are advised to update to the latest version.
 

Affected Products

Versions of the Elastic Network Drive Connector prior to 8.12.1

 

Resolved Vulnerabilities

Vulnerability in Elastic Network Drive Connector that allows access to documents denied read permission via the search application (CVE-2024-23447)

 

Vulnerability Patches

Vulnerability patches were made available in the February 7, 2024 update. Please follow the instructions on the reference site to update to the latest vulnerability patch version.

Elastic Network Drive Connector 8.12.1 and later versions

 

Referenced Sites

[1] CVE-2024-23447 Detail
https://nvd.nist.gov/vuln/detail/CVE-2024-23447
[2] Elastic Network Drive Connector 8.12.1 Security Update (ESA-2024-02)
https://discuss.elastic.co/t/elastic-network-drive-connector-8-12-1-security-update-esa-2024-02/352687/1
[3] Security issues
https://www.elastic.co/kr/community/security