ZeroHour

CVE-2018-3823

CVSS 3.1
5.4 medium
EPSS
<1%p49
Published
()
Modified
Description

X-Pack Machine Learning versions before 6.2.4 and 5.6.9 had a cross-site scripting (XSS) vulnerability. Users with manage_ml permissions could create jobs containing malicious data as part of their configuration that could allow the attacker to obtain sensitive information from or perform destructive actions on behalf of other ML users viewing the results of the jobs.

Vendors
elastic
Products
elasticsearch x-pack, kibana x-pack, logstash x-pack
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.