Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pgq6-ccqj-hpqr

Опубликовано: 04 мар. 2022
Источник: github
Github: Прошло ревью
CVSS3: 4.3

Описание

Elasticsearch privilege escalation

A flaw was discovered in Elasticsearch 7.17.0’s upgrade assistant, in which upgrading from version 6.x to 7.x would disable the in-built protections on the security index, allowing authenticated users with “*” index permissions access to this index. Users running a cluster on an affected version that had previously been upgraded from 6.x, should upgrade to 7.17.1. Users that are planning to upgrade from 6.x should not perform an upgrade from 6.x to versions 7.16 through 7.17.0 and should use 7.17.1+ for upgrades from 6.x.

Пакеты

Наименование

org.elasticsearch:elasticsearch

maven
Затронутые версииВерсия исправления

>= 7.16.0, < 7.17.1

7.17.1

EPSS

Процентиль: 47%
0.00245
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-269

Связанные уязвимости

CVSS3: 4.3
ubuntu
почти 4 года назад

A flaw was discovered in Elasticsearch 7.17.0’s upgrade assistant, in which upgrading from version 6.x to 7.x would disable the in-built protections on the security index, allowing authenticated users with “*” index permissions access to this index.

CVSS3: 4.3
redhat
почти 4 года назад

A flaw was discovered in Elasticsearch 7.17.0’s upgrade assistant, in which upgrading from version 6.x to 7.x would disable the in-built protections on the security index, allowing authenticated users with “*” index permissions access to this index.

CVSS3: 4.3
nvd
почти 4 года назад

A flaw was discovered in Elasticsearch 7.17.0’s upgrade assistant, in which upgrading from version 6.x to 7.x would disable the in-built protections on the security index, allowing authenticated users with “*” index permissions access to this index.

CVSS3: 4.3
debian
почти 4 года назад

A flaw was discovered in Elasticsearch 7.17.0\u2019s upgrade assistant ...

EPSS

Процентиль: 47%
0.00245
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-269