« Volver al listado

CVE-2026-33467

Estado: AnalizadaMedia (5.9)—

Improper Verification of Cryptographic Signature (CWE-347) in Elastic Package Registry could allow an attacker positioned to intercept network traffic, or to otherwise influence the contents served to a self-hosted registry, to substitute a tampered package without the integrity check failing closed.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-33467",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-33467",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-04-29T14:54:54.461695Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security@elastic.co",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.9,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "HIGH",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 2.2
      }
    ]
  },
  "affected": [
    {
      "source": "security@elastic.co",
      "affectedData": [
        {
          "vendor": "Elastic",
          "product": "Elastic Package Registry",
          "versions": [
            {
              "status": "affected",
              "version": "0.1.0",
              "versionType": "semver",
              "lessThanOrEqual": "1.37.0"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2026-04-28T22:16:48.823",
  "references": [
    {
      "url": "https://discuss.elastic.co/t/elastic-package-registry-1-38-0-security-update-esa-2026-27/386081",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security@elastic.co"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security@elastic.co",
      "description": [
        {
          "lang": "en",
          "value": "CWE-347"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Improper Verification of Cryptographic Signature (CWE-347) in Elastic Package Registry could allow an attacker positioned to intercept network traffic, or to otherwise influence the contents served to a self-hosted registry, to substitute a tampered package without the integrity check failing closed."
    },
    {
      "lang": "es",
      "value": "Verificación Incorrecta de Firma Criptográfica (CWE-347) en Elastic Package Registry podría permitir a un atacante posicionado para interceptar el tráfico de red, o para influir de otro modo en el contenido servido a un registro autoalojado, sustituir un paquete manipulado sin que la verificación de integridad falle cerrándose."
    }
  ],
  "lastModified": "2026-07-24T23:10:00.563",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:elastic:elastic_package_registry:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DCA1EBA8-B5AF-4AC8-A740-8E13E702B0ED",
              "versionEndExcluding": "1.38.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security@elastic.co"
}