X Pack
Vendor:
First CVE: Jun 5, 2017 · Active for 9 years
9
Total CVEs
More Total CVEs than 86% of tracked products
4.5
Avg CVEs / Year
Higher CVE frequency than 86% of tracked products
7.1
Avg CVSS
Higher Avg CVSS than 42% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact X Pack over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jun 5, 2017
9 years ago
Most Recent CVE
Mar 30, 2018
3,038 days ago
CVE Severity & Scoring
X Pack9 CVEs
56%
33%
11%
All CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (11.1%)
Network8 (88.9%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low8 (88.9%)
High1 (11.1%)
Unknown0 (0.0%)
User Interaction
None9 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low6 (66.7%)
High0 (0.0%)
None3 (33.3%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-3822CRITICAL X-Pack Security versions 6.2.0, 6.2.1, and 6.2.2 are vulnerable to a user impersonation attack via incorrect XML canonicalization and DOM traversal. An attacker might have been abl | Mar 30, 2018 | 9.8 | 30 | NO | NO |
CVE-2017-8448HIGH An error was found in the permission model used by X-Pack Alerting 5.0.0 to 5.6.0 whereby users mapped to certain built-in roles could create a watch that results in that user gain | Sep 29, 2017 | 8.8 | 27 | NO | NO |
CVE-2017-8438HIGH Elastic X-Pack Security versions 5.0.0 to 5.4.0 contain a privilege escalation bug in the run_as functionality. This bug prevents transitioning into the specified user specified in | Jun 5, 2017 | 8.8 | 27 | NO | NO |
CVE-2017-8450HIGH X-Pack 5.1.1 did not properly apply document and field level security to multi-search and multi-get requests so users without access to a document and/or field may have been able t | Jun 16, 2017 | 7.5 | 25 | NO | NO |
CVE-2017-8442MEDIUM Elasticsearch X-Pack Security versions 5.0.0 to 5.4.3, when enabled, can result in the Elasticsearch _nodes API leaking sensitive configuration information, such as the paths and p | Jul 7, 2017 | 6.5 | 22 | NO | NO |
CVE-2017-8447MEDIUM An error was found in the X-Pack Security 5.3.0 to 5.5.2 privilege enforcement. If a user has either 'delete' or 'index' permissions on an index in a cluster, they may be able to i | Sep 29, 2017 | 6.5 | 21 | NO | NO |
CVE-2017-8449MEDIUM X-Pack Security 5.2.x would allow access to more fields than the user should have seen if the field level security rules used a mix of grant and exclude rules when merging multiple | Jun 16, 2017 | 5.9 | 21 | NO | NO |
CVE-2017-8445MEDIUM An error was found in the X-Pack Security TLS trust manager for versions 5.0.0 to 5.5.1. If reloading the trust material fails the trust manager will be replaced with an instance t | Aug 18, 2017 | 5.5 | 18 | NO | NO |
CVE-2017-8441MEDIUM Elastic X-Pack Security versions prior to 5.4.1 and 5.3.3 did not always correctly apply Document Level Security to index aliases. This bug could allow a user with restricted permi | Jun 5, 2017 | 4.3 | 17 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (9 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (9 CVEs).
Media Mentions
Signals from CVEs in this product scope (9 CVEs).
Top CNAs Publishing CVEs For X Pack
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 6.2.2 | 1 | 9.8 | 1.6% | 0 | 0 |
| 6.2.1 | 1 | 9.8 | 1.6% | 0 | 0 |
| 6.2.0 | 1 | 9.8 | 1.6% | 0 | 0 |
| 5.6.0 | 1 | 8.8 | 0.8% | 0 | 0 |
| 5.5.2 | 2 | 7.7 | 0.7% | 0 | 0 |
| 5.5.0 | 2 | 7.7 | 0.7% | 0 | 0 |
| 5.4.0 | 3 | 8.0 | 0.8% | 0 | 0 |
| 5.3.3 | 3 | 8.0 | 0.8% | 0 | 0 |
| 5.3.2 | 3 | 8.0 | 0.8% | 0 | 0 |
| 5.3.1 | 3 | 8.0 | 0.8% | 0 | 0 |
| 5.3.0 | 3 | 8.0 | 0.8% | 0 | 0 |
| 5.2.2 | 2 | 8.8 | 0.9% | 0 | 0 |
| 5.2.1 | 2 | 8.8 | 0.9% | 0 | 0 |
| 5.2.0 | 2 | 8.8 | 0.9% | 0 | 0 |
| 5.1.1 | 3 | 8.4 | 0.9% | 0 | 0 |
| 5.1.0 | 1 | 8.8 | 1.0% | 0 | 0 |
| 5.0.2 | 2 | 8.8 | 0.9% | 0 | 0 |
| 5.0.1 | 2 | 8.8 | 0.9% | 0 | 0 |
| 5.0.0 | 2 | 8.8 | 0.9% | 0 | 0 |