CVE Database
/

CVE-2017-8438

Back to search

CVE-2017-8438

Published: Jun 5, 2017

Modified: Aug 5, 2024

PUBLISHED

Description

Elastic X-Pack Security versions 5.0.0 to 5.4.0 contain a privilege escalation bug in the run_as functionality. This bug prevents transitioning into the specified user specified in a run_as request. If a role has been created using a template that contains the _user properties, the behavior of run_as will be incorrect. Additionally if the run_as user specified does not exist, the transition will not happen.

VendorProductVersions

Elastic

X-Pack Security

affected
5.0.0 to 5.4.0

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now