VYPR

Logstash X Pack

by Elastic

CVEs (2)

  • CVE-2018-3824MedSep 19, 2018
    risk 0.40cvss 6.1epss 0.01

    X-Pack Machine Learning versions before 6.2.4 and 5.6.9 had a cross-site scripting (XSS) vulnerability. If an attacker is able to inject data into an index that has a ML job running against it, then when another user views the results of the ML job it could allow the attacker to…

  • CVE-2018-3823MedSep 19, 2018
    risk 0.35cvss 5.4epss 0.01

    X-Pack Machine Learning versions before 6.2.4 and 5.6.9 had a cross-site scripting (XSS) vulnerability. Users with manage_ml permissions could create jobs containing malicious data as part of their configuration that could allow the attacker to obtain sensitive information from…