Elasticsearch Security versions 6.5.0 and 6.5.1 contain an XXE flaw in Machine Learning's find_file_structure API. If a policy allowing external network access has been added to Elasticsearch's Java Security Manager then an attacker could send a specially crafted request capable of leaking content of local files on the Elasticsearch node. This could allow a user to access information that they should not have access to.
Advisories
Source ID Title
EUVD EUVD EUVD-2022-3560 Elasticsearch Security versions 6.5.0 and 6.5.1 contain an XXE flaw in Machine Learning's find_file_structure API. If a policy allowing external network access has been added to Elasticsearch's Java Security Manager then an attacker could send a specially crafted request capable of leaking content of local files on the Elasticsearch node. This could allow a user to access information that they should not have access to.
Github GHSA Github GHSA GHSA-ccmr-qj26-845g Improper Restriction of XML External Entity Reference in Elasticsearch
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: elastic

Published:

Updated: 2024-08-05T10:47:04.127Z

Reserved: 2018-09-20T00:00:00

Link: CVE-2018-17247

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2018-12-20T22:29:00.427

Modified: 2024-11-21T03:54:09.417

Link: CVE-2018-17247

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses