Elastic X-Pack Security versions 5.0.0 to 5.4.0 contain a privilege escalation bug in the run_as functionality. This bug prevents transitioning into the specified user specified in a run_as request. If a role has been created using a template that contains the _user properties, the behavior of run_as will be incorrect. Additionally if the run_as user specified does not exist, the transition will not happen.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: elastic

Published: 2017-06-05T14:00:00

Updated: 2024-08-05T16:34:22.961Z

Reserved: 2017-05-02T00:00:00

Link: CVE-2017-8438

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2017-06-05T14:29:00.280

Modified: 2019-10-09T23:30:13.487

Link: CVE-2017-8438

cve-icon Redhat

No data.