ElasticsearchGHSA-vpqm-88c4-x4cv
Exposure of Sensitive Information to an Unauthorized Actor in Elasticsearch
Medium6.5CVE-2018-17244 · Published May 13, 2022 · updated Nov 8, 2023
Elasticsearch Security versions 6.4.0 to 6.4.2 contain an error in the way request headers are applied to requests when using the Active Directory, LDAP, Native, or File realms. A request may receive headers intended for another request if the same username is being authenticated concurrently; when used with run as, this can result in the request running as the incorrect user. This could allow a user to access information that they should not have access to.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| org.elasticsearch:elasticsearch Maven | >= 6.4.0, < 6.4.3 | 6.4.3 |
Details and references
- CVSS 3.0
- CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-200
- Also known as
- CVE-2018-17244
More Elasticsearch advisories
All Elasticsearch| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| May 142022 | Improper Access Control in Elasticsearch | High7.5 | 1.6.0 |
| May 142022 | Improper Limitation of a Pathname to a Restricted Directory in Elasticsearch | Medium | 1.6.1 |
| May 132022 | Improper Restriction of XML External Entity Reference in Elasticsearch | Medium5.9 | 6.5.2 |
| May 132022 | Elasticsearch subject to cross site scripting | Medium6.1 | 5.6.9+1 more |
| May 132022 | Exposure of Sensitive Information to an Unauthorized Actor in Elasticsearch | High8.8 | 5.6.12+1 more |
| May 132022 | Improper Access Control in Elasticsearch | High8.1 | 5.6.15+1 more |