CVE-2017-8446

Severity CVSS v4.0:
Pending analysis
Type:
CWE-522 Insufficiently Protected Credentials
Publication date:
18/08/2017
Last modified:
20/04/2025

Description

The Reporting feature in X-Pack in versions prior to 5.5.2 and standalone Reporting plugin versions versions prior to 2.4.6 had an impersonation vulnerability. A user with the reporting_user role could execute a report with the permissions of another reporting user, possibly gaining access to sensitive data.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:elasticsearch:x-pack:*:*:*:*:*:*:*:* 5.5.1 (including)
cpe:2.3:a:elasticsearch:x-pack_reporting:*:*:*:*:*:*:*:* 2.4.5 (including)