Property
Languagehcl
Severitymedium
CWECWE-326: Inadequate Encryption Strength
OWASPA03:2017 - Sensitive Data Exposure
Confidence LevelMedium
Impact LevelMedium
Likelihood LevelLow

Description#

Node-to-node encryption is not enabled for your AWS Elasticsearch cluster, which means data transmitted between cluster nodes is not protected. This leaves internal traffic vulnerable to interception within your AWS environment.

Impact#

Without node-to-node encryption, sensitive data sent between Elasticsearch nodes can be exposed to attackers with network access, potentially leading to data breaches, unauthorized access, or compliance violations.