Description
X-Pack 5.1.1 did not properly apply document and field level security to multi-search and multi-get requests so users without access to a document and/or field may have been able to access this information.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2017-17400 | X-Pack 5.1.1 did not properly apply document and field level security to multi-search and multi-get requests so users without access to a document and/or field may have been able to access this information. |
References
| Link | Providers |
|---|---|
| https://www.elastic.co/community/security |
|
History
No history.
Status: PUBLISHED
Assigner: elastic
Published:
Updated: 2024-08-05T16:34:23.134Z
Reserved: 2017-05-02T00:00:00.000Z
Link: CVE-2017-8450
No data.
Status : Modified
Published: 2017-06-16T21:29:00.633
Modified: 2026-05-13T00:24:29.033
Link: CVE-2017-8450
No data.
OpenCVE Enrichment
No data.
EUVD