CVE-2017-8449: Infoleak
Published Jun 16, 2017
·Updated
X-Pack Security 5.2.x would allow access to more fields than the user should have seen if the field level security rules used a mix of grant and exclude rules when merging multiple rules with field level security rules for the same index.
Affected Software
1 affected component
Elastic X-Pack>=5.2.0<=5.2.2
Event History
Jun 16, 2017
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2017-8449?
CVE-2017-8449 has a moderate severity rating due to potential unauthorized access to sensitive data.
2
How do I fix CVE-2017-8449?
To fix CVE-2017-8449, upgrade to a version of X-Pack Security that is later than 5.2.2.
3
What kind of access does CVE-2017-8449 allow?
CVE-2017-8449 allows users to access more fields than they are permitted to view due to misconfigured field level security rules.
4
Which versions of Elastic X-Pack are affected by CVE-2017-8449?
CVE-2017-8449 affects Elastic X-Pack versions from 5.2.0 to 5.2.2 inclusive.
5
Is CVE-2017-8449 specific to certain indices?
Yes, CVE-2017-8449 is specific to indices where field level security rules have mixed grant and exclude configurations.