Elasticsearch CVE-2018-17247 XML External Entity Injection Vulnerability
BID:106294
CVE-2018-17247 |Info
Elasticsearch CVE-2018-17247 XML External Entity Injection Vulnerability
| Bugtraq ID: | 106294 |
| Class: | Design Error |
| CVE: |
CVE-2018-17247 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 20 2018 12:00AM |
| Updated: | Dec 20 2018 12:00AM |
| Credit: | The vendor reported this issue. |
| Vulnerable: |
Elasticsearch Elasticsearch 6.5.1 Elasticsearch Elasticsearch 6.5 |
| Not Vulnerable: |
Elasticsearch Elasticsearch 6.5.2 |
Discussion
Elasticsearch CVE-2018-17247 XML External Entity Injection Vulnerability
Elasticsearch is prone to an XML External Entity injection vulnerability.
Attackers can exploit this issue to obtain potentially sensitive information or cause a denial-of-service condition. This may lead to further attacks.
Elasticsearch versions 6.5.0 and 6.5.1 are vulnerable.
Elasticsearch is prone to an XML External Entity injection vulnerability.
Attackers can exploit this issue to obtain potentially sensitive information or cause a denial-of-service condition. This may lead to further attacks.
Elasticsearch versions 6.5.0 and 6.5.1 are vulnerable.
Exploit / POC
Elasticsearch CVE-2018-17247 XML External Entity Injection Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Elasticsearch CVE-2018-17247 XML External Entity Injection Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Elasticsearch CVE-2018-17247 XML External Entity Injection Vulnerability
References:
References:
- Elasticsearch Homepage (Elasticsearch)
- Elasticsearch Product Page (Elastic)
- Elasticsearch information disclosure (ESA-2018-19) (Elastic)