Medium severity4.3NVD Advisory· Published Jun 5, 2017· Updated May 13, 2026
CVE-2017-8441
CVE-2017-8441
Description
Elastic X-Pack Security versions prior to 5.4.1 and 5.3.3 did not always correctly apply Document Level Security to index aliases. This bug could allow a user with restricted permissions to view data they should not have access to when performing certain operations against an index alias.
Affected products
2- Elastic/X-Pack Securityv5Range: prior to 5.4.1 and 5.3.3
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- discuss.elastic.co/t/elastic-stack-5-4-1-and-5-3-3-security-updates/87952nvdVendor Advisory
- www.elastic.co/blog/elasticsearch-5-4-1-and-5-3-3-releasednvdRelease NotesVendor Advisory
- www.elastic.co/community/securitynvdVendor Advisory
News mentions
0No linked articles in our index yet.