CVE-2017-8441: Infoleak
Elastic X-Pack Security versions prior to 5.4.1 and 5.3.3 did not always correctly apply Document Level Security to index aliases. This bug could allow a user with restricted permissions to view data they should not have access to when performing certain operations against an index alias.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-8441?
CVE-2017-8441 is considered a high severity vulnerability due to its potential to allow restricted data access.
How do I fix CVE-2017-8441?
To fix CVE-2017-8441, upgrade to Elastic X-Pack version 5.3.3 or 5.4.1 or later.
Which versions are affected by CVE-2017-8441?
CVE-2017-8441 affects Elastic X-Pack versions prior to 5.4.1 and 5.3.3.
What impact does CVE-2017-8441 have on users?
CVE-2017-8441 may allow unauthorized users to access sensitive data through index aliases.
Is there a workaround for CVE-2017-8441?
No official workaround exists for CVE-2017-8441; the recommended action is to upgrade to a non-vulnerable version.