First published: Wed Sep 19 2018(Updated: )
X-Pack Machine Learning versions before 6.2.4 and 5.6.9 had a cross-site scripting (XSS) vulnerability. Users with manage_ml permissions could create jobs containing malicious data as part of their configuration that could allow the attacker to obtain sensitive information from or perform destructive actions on behalf of other ML users viewing the results of the jobs.
Credit: bressers@elastic.co
Affected Software | Affected Version | How to fix |
---|---|---|
Kibana X-Pack | <5.6.9 | |
Kibana X-Pack | >=6.0.0<6.2.4 | |
Kibana X-Pack | <5.6.9 | |
Kibana X-Pack | >=6.0.0<6.2.4 | |
Elastic X-Pack | <5.6.9 | |
Elastic X-Pack | >=6.1.0<6.2.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-3823 has a high severity rating due to the potential for unauthorized access to sensitive information.
To fix CVE-2018-3823, upgrade to Elasticsearch, Kibana, or Logstash versions 5.6.9 or later, or 6.2.4 or later.
CVE-2018-3823 is a cross-site scripting (XSS) vulnerability.
Users with manage_ml permissions are primarily affected by CVE-2018-3823.
An attacker could potentially obtain sensitive information or perform destructive actions using the XSS vulnerability in CVE-2018-3823.