Back to search
CVE-2017-8450
Published: Jun 16, 2017
Modified: Aug 5, 2024
PUBLISHED
Description
X-Pack 5.1.1 did not properly apply document and field level security to multi-search and multi-get requests so users without access to a document and/or field may have been able to access this information.
| Vendor | Product | Versions |
|---|---|---|
Elastic | Elastic X-Pack Security | affected 5.1.1 |
Weaknesses (CWE)
References
https://www.elastic.co/community/security
x_refsource_CONFIRM
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now