PT-2017-18341 · Elastic · X-Pack Security

Published

2017-06-16

·

Updated

2019-10-09

·

CVE-2017-8449

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions X-Pack Security versions 5.2.x
Description The issue allows access to more fields than the user should have seen when the field level security rules use a mix of grant and exclude rules, specifically when merging multiple rules with field level security rules for the same index.
Recommendations For X-Pack Security versions 5.2.x, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Incorrect Permission

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-8449

Affected Products

X-Pack Security