CVE-2018-17244: Infoleak
Elasticsearch Security versions 6.4.0 to 6.4.2 contain an error in the way request headers are applied to requests when using the Active Directory, LDAP, Native, or File realms. A request may receive headers intended for another request if the same username is being authenticated concurrently; when used with run as, this can result in the request running as the incorrect user. This could allow a user to access information that they should not have access to.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this Elasticsearch Security vulnerability?
The vulnerability ID for this Elasticsearch Security vulnerability is CVE-2018-17244.
What is the severity of CVE-2018-17244?
The severity of CVE-2018-17244 is medium with a severity value of 6.5.
Which versions of Elasticsearch Security are affected?
Elasticsearch Security versions 6.4.0 to 6.4.2 are affected.
What is the issue with request headers in this vulnerability?
In this vulnerability, there is an error in the way request headers are applied to requests when using the Active Directory, LDAP, Native, or File realms in Elasticsearch Security versions 6.4.0 to 6.4.2.
Are there any references for more information on this vulnerability?
Yes, you can find more information on this vulnerability at the following references: http://www.securityfocus.com/bid/106318, https://discuss.elastic.co/t/elastic-stack-6-4-3-and-5-6-13-security-update/155594, https://www.elastic.co/community/security.