CVE Vulnerabilities

CVE-2017-8448

Improper Privilege Management

Published: Sep 29, 2017 | Modified: Oct 09, 2019
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
6.5 MEDIUM
AV:N/AC:L/Au:S/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

An error was found in the permission model used by X-Pack Alerting 5.0.0 to 5.6.0 whereby users mapped to certain built-in roles could create a watch that results in that user gaining elevated privileges.

Weakness

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Affected Software

Name Vendor Start Version End Version
X-pack Elastic 5.0.0 (including) 5.0.0 (including)
X-pack Elastic 5.0.1 (including) 5.0.1 (including)
X-pack Elastic 5.0.2 (including) 5.0.2 (including)
X-pack Elastic 5.1.1 (including) 5.1.1 (including)
X-pack Elastic 5.2.0 (including) 5.2.0 (including)
X-pack Elastic 5.2.1 (including) 5.2.1 (including)
X-pack Elastic 5.2.2 (including) 5.2.2 (including)
X-pack Elastic 5.3.0 (including) 5.3.0 (including)
X-pack Elastic 5.3.1 (including) 5.3.1 (including)
X-pack Elastic 5.3.2 (including) 5.3.2 (including)
X-pack Elastic 5.3.3 (including) 5.3.3 (including)
X-pack Elastic 5.4.0 (including) 5.4.0 (including)
X-pack Elastic 5.5.0 (including) 5.5.0 (including)
X-pack Elastic 5.5.2 (including) 5.5.2 (including)
X-pack Elastic 5.6.0 (including) 5.6.0 (including)

Potential Mitigations

References