[Forgot Password]
Login  Register Subscribe

30430

 
 

423868

 
 

247621

 
 

909

 
 

194512

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

Path traversal vulnerability in Elasticsearch via incorrect XML canonicalization- CVE-2018-3822 (rpm)

ID: oval:org.secpod.oval:def:48180Date: (C)2018-10-24   (M)2023-03-29
Class: VULNERABILITYFamily: unix




The host is installed with Elasticsearch 6.2.0 before 6.2.3 and is prone to a path traversal vulnerability. A flaw is present in the application, which allows attackers to make use of the SAML Identity Provider to impersonate a legitimate user. On successful exploitation, an attacker might be able to register an account with an identifier that shares a suffix with a legitimate account.

Platform:
Linux
Product:
elasticsearch
Reference:
CVE-2018-3822
CVE    1
CVE-2018-3822
CPE    1
cpe:/a:elastic:elasticsearch

© SecPod Technologies