The Reporting feature in X-Pack in versions prior to 5.5.2 and standalone Reporting plugin versions versions prior to 2.4.6 had an impersonation vulnerability. A user with the reporting_user role could execute a report with the permissions of another reporting user, possibly gaining access to sensitive data.
References
Link Resource
https://www.elastic.co/community/security Vendor Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: elastic

Published: 2017-08-18T20:00:00

Updated: 2017-08-18T19:57:01

Reserved: 2017-05-02T00:00:00


Link: CVE-2017-8446

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2017-08-18T20:29:00.287

Modified: 2019-10-09T23:30:14.737


Link: CVE-2017-8446

JSON object: View

cve-icon Redhat Information

No data.