CVE-2023-31421: Elastic APM Server
High severity, CVSS 7.5. EPSS: 0.3% chance of exploitation in the next 30 days.
It was discovered that when acting as TLS clients, Beats, Elastic Agent, APM Server, and Fleet Server did not verify whether the server certificate is valid for the target IP address; however, certificate signature validation is still performed. More specifically, when the client is configured to connect to an IP address (instead of a hostname) it does not validate the server certificate's IP SAN values against that IP address and certificate validation fails, and therefore the connection is not blocked as expected.
Affected products
- Elastic APM Server: from 8.0.0, up to and including 8.9.2
- Elastic Elastic Agent: from 8.0.0, up to and including 8.9.2
- Elastic Elastic Beats: from 8.0.0, up to and including 8.9.2
- Elastic Elastic Fleet Server: from 8.0.0, up to and including 8.9.2
Published 2023-10-26. Last modified 2026-06-17.