Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gr96-2h6w-pf97

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

An error was found in the X-Pack Security 5.3.0 to 5.5.2 privilege enforcement. If a user has either 'delete' or 'index' permissions on an index in a cluster, they may be able to issue both delete and index requests against that index.

An error was found in the X-Pack Security 5.3.0 to 5.5.2 privilege enforcement. If a user has either 'delete' or 'index' permissions on an index in a cluster, they may be able to issue both delete and index requests against that index.

EPSS

Процентиль: 30%
0.00111
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-269
CWE-284

Связанные уязвимости

CVSS3: 6.5
nvd
больше 8 лет назад

An error was found in the X-Pack Security 5.3.0 to 5.5.2 privilege enforcement. If a user has either 'delete' or 'index' permissions on an index in a cluster, they may be able to issue both delete and index requests against that index.

EPSS

Процентиль: 30%
0.00111
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-269
CWE-284