Elastic X-Pack Security versions prior to 5.4.1 and 5.3.3 did not always correctly apply Document Level Security to index aliases. This bug could allow a user with restricted permissions to view data they should not have access to when performing certain operations against an index alias.
While it is executing, the product sets the permissions of an object in a way that violates the intended permissions that have been specified by the user.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://discuss.elastic.co/t/elastic-stack-5-4-1-and-5-3-3-security-updates/87952 | vendor advisory |
https://www.elastic.co/blog/elasticsearch-5-4-1-and-5-3-3-released | release notes vendor advisory |
https://www.elastic.co/community/security | vendor advisory |