CVE Database
/

CVE-2018-3822

Back to search

CVE-2018-3822

Published: Mar 30, 2018

Modified: Aug 5, 2024

PUBLISHED

Description

X-Pack Security versions 6.2.0, 6.2.1, and 6.2.2 are vulnerable to a user impersonation attack via incorrect XML canonicalization and DOM traversal. An attacker might have been able to impersonate a legitimate user if the SAML Identity Provider allows for self registration with arbitrary identifiers and the attacker can register an account which an identifier that shares a suffix with a legitimate account. Both of those conditions must be true in order to exploit this flaw.

VendorProductVersions

Elastic

X-Pack Security

affected
6.2.0, 6.2.1, and 6.2.2

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now