Medium severity6.5NVD Advisory· Published Sep 29, 2017· Updated May 13, 2026
CVE-2017-8447
CVE-2017-8447
Description
An error was found in the X-Pack Security 5.3.0 to 5.5.2 privilege enforcement. If a user has either 'delete' or 'index' permissions on an index in a cluster, they may be able to issue both delete and index requests against that index.
Affected products
8cpe:2.3:a:elastic:x-pack:5.3.0:*:*:*:*:*:*:*+ 6 more
- cpe:2.3:a:elastic:x-pack:5.3.0:*:*:*:*:*:*:*
- cpe:2.3:a:elastic:x-pack:5.3.1:*:*:*:*:*:*:*
- cpe:2.3:a:elastic:x-pack:5.3.2:*:*:*:*:*:*:*
- cpe:2.3:a:elastic:x-pack:5.3.3:*:*:*:*:*:*:*
- cpe:2.3:a:elastic:x-pack:5.4.0:*:*:*:*:*:*:*
- cpe:2.3:a:elastic:x-pack:5.5.0:*:*:*:*:*:*:*
- cpe:2.3:a:elastic:x-pack:5.5.2:*:*:*:*:*:*:*
- Elastic/Elastic X-Pack Securityv5Range: 5.3.0 to 5.5.2
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- discuss.elastic.co/t/x-pack-security-5-6-0-and-5-5-3-security-update/100089nvdMitigationVendor Advisory
News mentions
0No linked articles in our index yet.