SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2018-3824

X-Pack Machine Learning versions before 6.2.4 and 5.6.9 had a cross-site scripting (XSS) vulnerability.

MEDIUM 6.1EPSS 0.89%

Does this matter?

Lower severity and a low EPSS score (0.89%). Track it; it rarely justifies an emergency change on its own.

Description

X-Pack Machine Learning versions before 6.2.4 and 5.6.9 had a cross-site scripting (XSS) vulnerability. If an attacker is able to inject data into an index that has a ML job running against it, then when another user views the results of the ML job it could allow the attacker to obtain sensitive information from or perform destructive actions on behalf of that other ML user.

CVSS 3.0
6.1 MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS
0.89% probability · 57th percentile
CISA KEV
Not listed
Weakness
CWE-79
Affected
elastic/elasticsearch x-pack · elastic/kibana x-pack · elastic/logstash x-pack
Source
security@elastic.co

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.