CVE Database
/

CVE-2017-8447

Back to search

CVE-2017-8447

Published: Sep 28, 2017

Modified: Aug 5, 2024

PUBLISHED

Description

An error was found in the X-Pack Security 5.3.0 to 5.5.2 privilege enforcement. If a user has either 'delete' or 'index' permissions on an index in a cluster, they may be able to issue both delete and index requests against that index.

VendorProductVersions

Elastic

Elastic X-Pack Security

affected
5.3.0 to 5.5.2

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now