GHSA-mjpc-qx7h-r8c9
Dashboard / Vulnerabilities / GHSA-mjpc-qx7h-r8c9
Summary: Elasticsearch subject to cross site scripting
Details: X-Pack Machine Learning versions before 6.2.4 and 5.6.9 had a cross-site scripting (XSS) vulnerability. If an attacker is able to inject data into an index that has a ML job running against it, then when another user views the results of the ML job it could allow the attacker to obtain sensitive information from or perform destructive actions on behalf of that other ML user.
References: https://nvd.nist.gov/vuln/detail/CVE-2018-3824, https://discuss.elastic.co/t/elastic-stack-6-2-4-and-5-6-9-security-update/128422, https://www.elastic.co/community/security
Affected packages
Package
Name: org.elasticsearch:elasticsearch
Purl: pkg:maven/org.elasticsearch/elasticsearch
Affected ranges
Type: ECOSYSTEM
Events:
