Intel

AIKIDO-2025-10002

github.com/elastic/elastic-agent-libs/transport is vulnerable to Use of Weak Hash

Use of Weak Hash Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Jan 2, 2025

25

Low Risk

This Affects:

Are you affected? Scan for Free

TL;DR

Affected versions of this package are affected by weak encryption caused by the absence of a Subject Key Identifier (SKI) in Go. As demonstrated in RFC 5280, when the SKI is missing, its generation depends on SHA-1, a deprecated algorithm due to its susceptibility to collision attacks.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

github.com/elastic/elastic-agent-libs/transport is vulnerable to Use of Weak Hash in versions 0.2.4 - 0.17.5.

How to fix this

Upgrade the github.com/elastic/elastic-agent-libs/transport library to the patch version.