Filtered by vendor Elasticsearch
Subscriptions
Filtered by product X-pack
Subscriptions
Total
1 CVE
CVE | Vendors | Products | Updated | CVSS v3.1 |
---|---|---|---|---|
CVE-2017-8446 | 1 Elasticsearch | 2 X-pack, X-pack Reporting | 2024-08-05 | N/A |
The Reporting feature in X-Pack in versions prior to 5.5.2 and standalone Reporting plugin versions versions prior to 2.4.6 had an impersonation vulnerability. A user with the reporting_user role could execute a report with the permissions of another reporting user, possibly gaining access to sensitive data. |
Page 1 of 1.