CVE Database
/

CVE-2018-17247

Back to search

CVE-2018-17247

Published: Dec 20, 2018

Modified: Aug 5, 2024

PUBLISHED

Description

Elasticsearch Security versions 6.5.0 and 6.5.1 contain an XXE flaw in Machine Learning's find_file_structure API. If a policy allowing external network access has been added to Elasticsearch's Java Security Manager then an attacker could send a specially crafted request capable of leaking content of local files on the Elasticsearch node. This could allow a user to access information that they should not have access to.

VendorProductVersions

Elastic

Elasticsearch

affected
6.5.0 and 6.5.1

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now