X-Pack 5.1.1 did not properly apply document and field level security to multi-search and multi-get requests so users without access to a document and/or field may have been able to access this information.
oryginał ENCVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NElastic X Pack
APPElastic5.1.1
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
Powiązane podatności
CVE-2018-3822CRITICAL9.8PL ✓ten sam produkt
Elastic X-Pack Security: podszywanie się pod użytkownika przez błąd SAML
CVE-2017-8448HIGH8.8ten sam produkt
An error was found in the permission model used by X-Pack Alerting 5.0.0 to 5.6.0 whereby users mapped to cert...
CVE-2017-8438HIGH8.8ten sam produkt
Elastic X-Pack Security versions 5.0.0 to 5.4.0 contain a privilege escalation bug in the run_as functionality...
CVE-2017-8447MEDIUM6.5ten sam produkt
An error was found in the X-Pack Security 5.3.0 to 5.5.2 privilege enforcement. If a user has either 'delete' ...
CVE-2017-8445MEDIUM5.5ten sam produkt
An error was found in the X-Pack Security TLS trust manager for versions 5.0.0 to 5.5.1. If reloading the trus...