← Back

CVE-2017-8448

nvd nist
Published: Sep 29, 2017Modified: May 13, 2026

JSON object

Loading...
8.8
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD

Description

An error was found in the permission model used by X-Pack Alerting 5.0.0 to 5.6.0 whereby users mapped to certain built-in roles could create a watch that results in that user gaining elevated privileges.

Affected (15)

Products: Elastic: X Pack
1 product
X Pack
Configuration A
15 vulnerable
Vulnerable SoftwareAffected Versions
Elastic
Version 5.0.0
Version 5.0.1
Version 5.0.2
Version 5.1.1
Version 5.2.0
Version 5.2.1
Version 5.2.2
Version 5.3.0
Version 5.3.1
Version 5.3.2
Version 5.3.3
Version 5.4.0
Version 5.5.0
Version 5.5.2
Version 5.6.0

References (2)

Source: af854a3a-2127-422b-91ae-364da2661108
MitigationVendor Advisory

Timeline

No history available yet.