2023-04-24 12:24:31 +02:00
{
"id" : "CVE-2017-8447" ,
"sourceIdentifier" : "bressers@elastic.co" ,
"published" : "2017-09-29T01:34:50.577" ,
2024-11-23 09:11:19 +00:00
"lastModified" : "2024-11-21T03:34:02.157" ,
2023-04-24 12:24:31 +02:00
"vulnStatus" : "Modified" ,
2024-12-08 03:06:42 +00:00
"cveTags" : [ ] ,
2023-04-24 12:24:31 +02:00
"descriptions" : [
{
"lang" : "en" ,
"value" : "An error was found in the X-Pack Security 5.3.0 to 5.5.2 privilege enforcement. If a user has either 'delete' or 'index' permissions on an index in a cluster, they may be able to issue both delete and index requests against that index."
} ,
{
"lang" : "es" ,
"value" : "Existe un error en torno al cumplimiento de los privilegios en X-Pack Security desde la versi\u00f3n 5.3.0 hasta la 5.5.2 Si un usuario tiene los permisos de \"delete\" o \"index\" en un \u00edndice en un cl\u00faster, podr\u00eda enviar las peticiones de delete e index contra el \u00edndice."
}
] ,
"metrics" : {
"cvssMetricV30" : [
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"cvssData" : {
"version" : "3.0" ,
"vectorString" : "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" ,
2024-11-23 09:11:19 +00:00
"baseScore" : 6.5 ,
"baseSeverity" : "MEDIUM" ,
2023-04-24 12:24:31 +02:00
"attackVector" : "NETWORK" ,
"attackComplexity" : "LOW" ,
"privilegesRequired" : "LOW" ,
"userInteraction" : "NONE" ,
"scope" : "UNCHANGED" ,
"confidentialityImpact" : "NONE" ,
"integrityImpact" : "HIGH" ,
2024-11-23 09:11:19 +00:00
"availabilityImpact" : "NONE"
2023-04-24 12:24:31 +02:00
} ,
"exploitabilityScore" : 2.8 ,
"impactScore" : 3.6
}
] ,
"cvssMetricV2" : [
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"cvssData" : {
"version" : "2.0" ,
"vectorString" : "AV:N/AC:L/Au:S/C:N/I:P/A:P" ,
2024-11-23 09:11:19 +00:00
"baseScore" : 5.5 ,
2023-04-24 12:24:31 +02:00
"accessVector" : "NETWORK" ,
"accessComplexity" : "LOW" ,
"authentication" : "SINGLE" ,
"confidentialityImpact" : "NONE" ,
"integrityImpact" : "PARTIAL" ,
2024-11-23 09:11:19 +00:00
"availabilityImpact" : "PARTIAL"
2023-04-24 12:24:31 +02:00
} ,
"baseSeverity" : "MEDIUM" ,
"exploitabilityScore" : 8.0 ,
"impactScore" : 4.9 ,
"acInsufInfo" : false ,
"obtainAllPrivilege" : false ,
"obtainUserPrivilege" : false ,
"obtainOtherPrivilege" : false ,
"userInteractionRequired" : false
}
]
} ,
"weaknesses" : [
{
2024-11-23 09:11:19 +00:00
"source" : "bressers@elastic.co" ,
"type" : "Secondary" ,
2023-04-24 12:24:31 +02:00
"description" : [
{
"lang" : "en" ,
2024-11-23 09:11:19 +00:00
"value" : "CWE-284"
2023-04-24 12:24:31 +02:00
}
]
} ,
{
2024-11-23 09:11:19 +00:00
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
2023-04-24 12:24:31 +02:00
"description" : [
{
"lang" : "en" ,
2024-11-23 09:11:19 +00:00
"value" : "CWE-269"
2023-04-24 12:24:31 +02:00
}
]
}
] ,
"configurations" : [
{
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:elastic:x-pack:5.3.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "761A9E6A-DBC5-48E4-8A79-A90F65C28E0F"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:elastic:x-pack:5.3.1:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "8BAAB65B-1C7C-4929-ACAA-9993E1626FF6"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:elastic:x-pack:5.3.2:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "BE9F72ED-C37A-435D-9253-801C97C50753"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:elastic:x-pack:5.3.3:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "965A9F08-9C79-436D-98BA-DAC4F5D71EF7"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:elastic:x-pack:5.4.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "86D9F09D-81BD-4B6E-8016-E6EAF2D68E5D"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:elastic:x-pack:5.5.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "BAF02F57-1183-4A26-98ED-90D43C8E1472"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:elastic:x-pack:5.5.2:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "F38E001E-D799-4F5E-BF62-E8F58EF7B8BE"
}
]
}
]
}
] ,
"references" : [
{
"url" : "https://discuss.elastic.co/t/x-pack-security-5-6-0-and-5-5-3-security-update/100089" ,
"source" : "bressers@elastic.co" ,
"tags" : [
"Mitigation" ,
"Vendor Advisory"
]
2024-11-23 09:11:19 +00:00
} ,
{
"url" : "https://discuss.elastic.co/t/x-pack-security-5-6-0-and-5-5-3-security-update/100089" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Mitigation" ,
"Vendor Advisory"
]
2023-04-24 12:24:31 +02:00
}
]
}