QID 996949

Date Published: 2024-01-30

QID 996949: Java (Maven) Security Update for org.elasticsearch:elasticsearch (GHSA-mjpc-qx7h-r8c9)

X-Pack Machine Learning versions before 6.2.4 and 5.6.9 had a cross-site scripting (XSS) vulnerability. If an attacker is able to inject data into an index that has a ML job running against it, then when another user views the results of the ML job it could allow the attacker to obtain sensitive information from or perform destructive actions on behalf of that other ML user.

Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.

  • CVSS V3 rated as High - 6.1 severity.
  • CVSS V2 rated as Medium - 4.3 severity.
  • Solution
    Refer to Github security advisory GHSA-mjpc-qx7h-r8c9 for updates and patch information.
    Vendor References

    CVEs related to QID 996949

    Software Advisories
    Advisory ID Software Component Link
    GHSA-mjpc-qx7h-r8c9 org.elasticsearch:elasticsearch URL Logo github.com/advisories/GHSA-mjpc-qx7h-r8c9