CVE-2017-8446: Medium severity kibana x-pack vulnerability
The Reporting feature in X-Pack in versions prior to 5.5.2 and standalone Reporting plugin versions versions prior to 2.4.6 had an impersonation vulnerability. A user with the reportinguser role could execute a report with the permissions of another reporting user, possibly gaining access to sensitive data.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-8446?
CVE-2017-8446 is considered to have a high severity rating due to its potential for unauthorized access to sensitive reports.
How do I fix CVE-2017-8446?
To fix CVE-2017-8446, upgrade to Elastic X-Pack version 5.5.2 or later and standalone Reporting plugin version 2.4.6 or later.
Who is affected by CVE-2017-8446?
Users with the reporting_user role using affected versions of X-Pack or the Reporting plugin are vulnerable to CVE-2017-8446.
What types of systems are impacted by CVE-2017-8446?
CVE-2017-8446 impacts systems running Elasticsearch with X-Pack versions prior to 5.5.2 and Reporting plugin versions prior to 2.4.6.
What kind of vulnerability is CVE-2017-8446?
CVE-2017-8446 is an impersonation vulnerability that allows unauthorized report execution with elevated permissions.