CVE-2017-8441
05.06.2017, 14:29
Elastic X-Pack Security versions prior to 5.4.1 and 5.3.3 did not always correctly apply Document Level Security to index aliases. This bug could allow a user with restricted permissions to view data they should not have access to when performing certain operations against an index alias.Enginsight
Vendor | Product | Version |
---|---|---|
elastic | x-pack | 5.3.0 ≤ 𝑥 < 5.3.3 |
elastic | x-pack | 5.4.0 ≤ 𝑥 < 5.4.1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-279 - Incorrect Execution-Assigned PermissionsWhile it is executing, the software sets the permissions of an object in a way that violates the intended permissions that have been specified by the user.
- CWE-200 - Exposure of Sensitive Information to an Unauthorized ActorThe product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
References