← back
CVE-2017-8441

CVE-2017-8441

EPSS 0.7%CWE-279
Elastic X-Pack Security versions prior to 5.4.1 and 5.3.3 did not always correctly apply Document Level Security to index aliases. This bug could allow a user with restricted permissions to view data they should not have access to when performing certain operations against an index alias.

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →