CVEs (2)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Elastic 3Elasticsearch X Pack Kibana X PackLogstash X PackNov 21, 2024 Sep 19, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 X-Pack Machine Learning versions before 6.2.4 and 5.6.9 had a cross-site scripting (XSS) vulnerability. If an attacker is able to inject data into an index that has a ML job running against it, then when another user vie...Show more |
1Elastic 3Elasticsearch X Pack Kibana X PackLogstash X PackNov 21, 2024 Sep 19, 2018 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 X-Pack Machine Learning versions before 6.2.4 and 5.6.9 had a cross-site scripting (XSS) vulnerability. Users with manage_ml permissions could create jobs containing malicious data as part of their configuration that cou...Show more |