Home
MEDIUM: 5.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:NDefault status
unaffected
7.0.0 (semver)
affected
8.14.0 (semver)
affected
8.19.0 (semver)
affected
9.0.0 (semver)
affected
9.1.0 (semver)
affected
Description
Insufficiently Protected Credentials in the Crowdstrike connector can lead to Crowdstrike credentials being leaked. A malicious user can access cached credentials from a Crowdstrike connector in another space by creating and running a Crowdstrike connector in a space to which they have access.
Problem types
CWE-522 Insufficiently Protected Credentials
Product status
7.0.0 (semver)
8.14.0 (semver)
8.19.0 (semver)
9.0.0 (semver)
9.1.0 (semver)
References
discuss.elastic.co/...1-5-security-update-esa-2025-19/382455
discuss.elastic.co/...1-5-security-update-esa-2025-19/382455