Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The Reporting feature in X-Pack in versions prior to 5.5.2 and standalone Reporting plugin versions versions prior to 2.4.6 had an impersonation vulnerability. A user with the reporting_user role could execute a report with the permissions of another reporting user, possibly gaining access to sensitive data.
CVSS Information
N/A
Vulnerability Type
不充分的凭证保护机制
Vulnerability Title
Elasticsearch X-Pack和Reporting插件安全漏洞
Vulnerability Description
Elasticsearch X-Pack是是荷兰Elasticsearch公司的一个Elastic Stack(日志分析系统)的扩展。Reporting是一款应用在其中的插件,也可以独立使用。 Elasticsearch X-Pack 5.5.2之前的版本和Reporting插件2.4.6之前的版本中的Reporting功能存在安全漏洞。攻击者可利用该漏洞以其他用户权限执行操作,可能获取敏感信息的访问权限。
CVSS Information
N/A
Vulnerability Type
N/A