PT-2017-18341 · Elastic · X-Pack Security

Publicado

2017-06-16

·

Atualizado

2019-10-09

·

CVE-2017-8449

CVSS v3.1

5.9

Média

VetorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions X-Pack Security versions 5.2.x
Description The issue allows access to more fields than the user should have seen when the field level security rules use a mix of grant and exclude rules, specifically when merging multiple rules with field level security rules for the same index.
Recommendations For X-Pack Security versions 5.2.x, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Incorrect Permission

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-8449

Produtos afetados

X-Pack Security