Improper Certificate Validation Affecting org.elasticsearch.plugin:x-pack-security package, versions [7.8.1,8.19.8)[9.0.0-beta1,9.1.8)[9.2.0,9.2.2)


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.19% (10th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-JAVA-ORGELASTICSEARCHPLUGIN-14417580
  • published16 Dec 2025
  • disclosed15 Dec 2025
  • creditUnknown

Introduced: 15 Dec 2025

CVE-2025-37731  (opens in a new tab)
CWE-295  (opens in a new tab)

How to fix?

Upgrade org.elasticsearch.plugin:x-pack-security to version 8.19.8, 9.1.8, 9.2.2 or higher.

Overview

org.elasticsearch.plugin:x-pack-security is an Elasticsearch Expanded Pack Plugin - Security

Affected versions of this package are vulnerable to Improper Certificate Validation via the PKI realm. An attacker can impersonate other users by presenting specially crafted client certificates signed by a trusted Certificate Authority.

Note: This is only exploitable if the attacker possesses a client certificate signed by a legitimate, trusted Certificate Authority.

CVSS Base Scores

version 4.0
version 3.1