CVE Database
/

CVE-2017-8449

Back to search

CVE-2017-8449

Published: Jun 16, 2017

Modified: Aug 5, 2024

PUBLISHED

Description

X-Pack Security 5.2.x would allow access to more fields than the user should have seen if the field level security rules used a mix of grant and exclude rules when merging multiple rules with field level security rules for the same index.

VendorProductVersions

Elastic

Elastic X-Pack Security

affected
before 5.3.0

Weaknesses (CWE)

References

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now