An error was found in the permission model used by X-Pack Alerting 5.0.0 to 5.6.0 whereby users mapped to certain built-in roles could create a watch that results in that user gaining elevated privileges.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HElastic X Pack
APPElastic5.0.05.0.15.0.25.1.15.2.05.2.15.2.25.3.05.3.15.3.25.3.35.4.05.5.05.5.25.6.0
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Related vulnerabilities
CVE-2018-3822CRITICAL9.8PL ✓same product
Elastic X-Pack Security: podszywanie się pod użytkownika przez błąd SAML
CVE-2017-8450HIGH7.5same product
X-Pack 5.1.1 did not properly apply document and field level security to multi-search and multi-get requests s...
CVE-2017-8438HIGH8.8same product
Elastic X-Pack Security versions 5.0.0 to 5.4.0 contain a privilege escalation bug in the run_as functionality...
CVE-2017-8447MEDIUM6.5same product
An error was found in the X-Pack Security 5.3.0 to 5.5.2 privilege enforcement. If a user has either 'delete' ...
CVE-2017-8445MEDIUM5.5same product
An error was found in the X-Pack Security TLS trust manager for versions 5.0.0 to 5.5.1. If reloading the trus...