ElasticsearchGHSA-ccmr-qj26-845g
Improper Restriction of XML External Entity Reference in Elasticsearch
Medium5.9CVE-2018-17247 · Published May 13, 2022 · updated Nov 8, 2023
Elasticsearch Security versions 6.5.0 and 6.5.1 contain an XXE flaw in Machine Learning's find_file_structure API. If a policy allowing external network access has been added to Elasticsearch's Java Security Manager then an attacker could send a specially crafted request capable of leaking content of local files on the Elasticsearch node. This could allow a user to access information that they should not have access to.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| org.elasticsearch:elasticsearch Maven | >= 6.5.0, < 6.5.2 | 6.5.2 |
Details and references
- CVSS 3.0
- CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-611
- Also known as
- CVE-2018-17247
More Elasticsearch advisories
All Elasticsearch| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| May 142022 | Improper Access Control in Elasticsearch | High7.5 | 1.6.0 |
| May 142022 | Improper Limitation of a Pathname to a Restricted Directory in Elasticsearch | Medium | 1.6.1 |
| May 132022 | Exposure of Sensitive Information to an Unauthorized Actor in Elasticsearch | Medium6.5 | 6.4.3 |
| May 132022 | Elasticsearch subject to cross site scripting | Medium6.1 | 5.6.9+1 more |
| May 132022 | Exposure of Sensitive Information to an Unauthorized Actor in Elasticsearch | High8.8 | 5.6.12+1 more |
| May 132022 | Improper Access Control in Elasticsearch | High8.1 | 5.6.15+1 more |