Vulnerability Details CVE-2017-8446
The Reporting feature in X-Pack in versions prior to 5.5.2 and standalone Reporting plugin versions versions prior to 2.4.6 had an impersonation vulnerability. A user with the reporting_user role could execute a report with the permissions of another reporting user, possibly gaining access to sensitive data.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 35.5%
CVSS Severity
CVSS v3 Score 5.3
CVSS v2 Score 4.0
Products affected by CVE-2017-8446
-
cpe:2.3:a:elasticsearch:x-pack:5.5.1
-
cpe:2.3:a:elasticsearch:x-pack_reporting:2.4.5