First published: Fri Aug 18 2017(Updated: )
The Reporting feature in X-Pack in versions prior to 5.5.2 and standalone Reporting plugin versions versions prior to 2.4.6 had an impersonation vulnerability. A user with the reporting_user role could execute a report with the permissions of another reporting user, possibly gaining access to sensitive data.
Credit: bressers@elastic.co
Affected Software | Affected Version | How to fix |
---|---|---|
Kibana X-Pack | <=5.5.1 | |
Kibana Reporting | <=2.4.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-8446 is considered to have a high severity rating due to its potential for unauthorized access to sensitive reports.
To fix CVE-2017-8446, upgrade to Elastic X-Pack version 5.5.2 or later and standalone Reporting plugin version 2.4.6 or later.
Users with the reporting_user role using affected versions of X-Pack or the Reporting plugin are vulnerable to CVE-2017-8446.
CVE-2017-8446 impacts systems running Elasticsearch with X-Pack versions prior to 5.5.2 and Reporting plugin versions prior to 2.4.6.
CVE-2017-8446 is an impersonation vulnerability that allows unauthorized report execution with elevated permissions.