First published: Fri Aug 18 2017(Updated: )
The Reporting feature in X-Pack in versions prior to 5.5.2 and standalone Reporting plugin versions versions prior to 2.4.6 had an impersonation vulnerability. A user with the reporting_user role could execute a report with the permissions of another reporting user, possibly gaining access to sensitive data.
Credit: bressers@elastic.co
Affected Software | Affected Version | How to fix |
---|---|---|
Elasticsearch X-pack | <=5.5.1 | |
Elasticsearch X-pack Reporting | <=2.4.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.