Network misconfigurations

Elasticsearch is not using HTTPS

Platform(s)
Compliance Frameworks
  • CCPA
  • ,
  • CPRA
  • ,
  • iso_27001_2022
  • ,
  • iso_27002_2022
  • ,
  • NIST 800-171
  • ,
  • NIST 800-53
  • ,
  • Orca Best Practices
  • ,
  • PDPA
  • ,
  • UK Cyber Essentials

Description

Elasticsearch is not running with HTTPS. HTTPS uses TLS to encrypt client connections and those between different components of the Elastic stack (Logstash, Kibana, Elasticsearch). Without TLS, you run the risk of eavesdropping and man-in-the-middle attacks.