Thursday, May 30, 2019

Exploring Elasticsearch Vulnerabilities

You’ve probably heard of a recent data breach involving Elasticsearch. Indeed, not a month goes by where we don’t come across an article or research showcasing a set of sensitive information exposed on an Elasticsearch cluster.

A substantial amount of this research into vulnerable Elasticsearch instances is conducted by Bob Diachenko, a security analyst and consultant at Security Discovery. For example, a big discovery at the beginning of the year involved millions of sensitive files, including home loan applications, credit reports, bankruptcy records, and more.



from DZone.com Feed http://bit.ly/2WevDvD

No comments:

Post a Comment