← Back

CVE-2017-14730

nvd nist
Published: Sep 25, 2017Modified: May 13, 2026

JSON object

Loading...
7.8
Vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD

Description

The init script in the Gentoo app-admin/logstash-bin package before 5.5.3 and 5.6.x before 5.6.1 has "chown -R" calls for user-writable directory trees, which allows local users to gain privileges by leveraging access to a $LS_USER account for creation of a hard link.

Affected (17)

1 product
Logstash
Configuration A
17 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Elasticsearch
Version 5.0.0
Version 5.0.1
Version 5.0.2
Version 5.1.1
Version 5.1.2
Version 5.2.0
Version 5.2.1
Version 5.3.0
Version 5.3.1
Version 5.3.2
Version 5.4.1
Version 5.4.2
Version 5.4.3
Version 5.5.0
Version 5.5.1
Version 5.5.2
Version 5.6.0
Running on/withPlatform Versions
Gentoo
Linux
All versions

References (8)

Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

Timeline

No history available yet.