Elasticsearch subject to cross site scripting
Moderate severity
GitHub Reviewed
Published
May 13, 2022
to the GitHub Advisory Database
•
Updated Jan 8, 2024
Package
Affected versions
< 5.6.9
>= 6.0.0, < 6.2.4
Patched versions
5.6.9
6.2.4
Description
Published by the National Vulnerability Database
Sep 19, 2018
Published to the GitHub Advisory Database
May 13, 2022
Last updated
Jan 8, 2024
Reviewed
Jan 8, 2024
X-Pack Machine Learning versions before 6.2.4 and 5.6.9 had a cross-site scripting (XSS) vulnerability. If an attacker is able to inject data into an index that has a ML job running against it, then when another user views the results of the ML job it could allow the attacker to obtain sensitive information from or perform destructive actions on behalf of that other ML user.
References