CVE Database
/

CVE-2017-8446

Back to search

CVE-2017-8446

Published: Aug 18, 2017

Modified: Aug 5, 2024

PUBLISHED

Description

The Reporting feature in X-Pack in versions prior to 5.5.2 and standalone Reporting plugin versions versions prior to 2.4.6 had an impersonation vulnerability. A user with the reporting_user role could execute a report with the permissions of another reporting user, possibly gaining access to sensitive data.

VendorProductVersions

Elastic

Elastic X-Pack Reporting

affected
Before 5.5.2 and 2.4.6

Weaknesses (CWE)

References

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now