X Pack

Vendor:

First CVE: Jun 5, 2017 · Active for 9 years

9
Total CVEs
More Total CVEs than 86% of tracked products
4.5
Avg CVEs / Year
Higher CVE frequency than 86% of tracked products
7.1
Avg CVSS
Higher Avg CVSS than 42% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact X Pack over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 5, 2017
9 years ago
Most Recent CVE
Mar 30, 2018
3,038 days ago

CVE Severity & Scoring

X Pack9 CVEs
All CVEs352,231 CVEs
MediumHighCritical
Attack Vector
Local1 (11.1%)
Network8 (88.9%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low8 (88.9%)
High1 (11.1%)
Unknown0 (0.0%)
User Interaction
None9 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low6 (66.7%)
High0 (0.0%)
None3 (33.3%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (9 CVEs).

9 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
X-Pack Security versions 6.2.0, 6.2.1, and 6.2.2 are vulnerable to a user impersonation attack via incorrect XML canonicalization and DOM traversal. An attacker might have been abl
Mar 30, 20189.830NONO
An error was found in the permission model used by X-Pack Alerting 5.0.0 to 5.6.0 whereby users mapped to certain built-in roles could create a watch that results in that user gain
Sep 29, 20178.827NONO
Elastic X-Pack Security versions 5.0.0 to 5.4.0 contain a privilege escalation bug in the run_as functionality. This bug prevents transitioning into the specified user specified in
Jun 5, 20178.827NONO
X-Pack 5.1.1 did not properly apply document and field level security to multi-search and multi-get requests so users without access to a document and/or field may have been able t
Jun 16, 20177.525NONO
Elasticsearch X-Pack Security versions 5.0.0 to 5.4.3, when enabled, can result in the Elasticsearch _nodes API leaking sensitive configuration information, such as the paths and p
Jul 7, 20176.522NONO
An error was found in the X-Pack Security 5.3.0 to 5.5.2 privilege enforcement. If a user has either 'delete' or 'index' permissions on an index in a cluster, they may be able to i
Sep 29, 20176.521NONO
X-Pack Security 5.2.x would allow access to more fields than the user should have seen if the field level security rules used a mix of grant and exclude rules when merging multiple
Jun 16, 20175.921NONO
An error was found in the X-Pack Security TLS trust manager for versions 5.0.0 to 5.5.1. If reloading the trust material fails the trust manager will be replaced with an instance t
Aug 18, 20175.518NONO
Elastic X-Pack Security versions prior to 5.4.1 and 5.3.3 did not always correctly apply Document Level Security to index aliases. This bug could allow a user with restricted permi
Jun 5, 20174.317NONO

Exploit Exposure

Signals from CVEs in this product scope (9 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (9 CVEs).

Media Mentions

Signals from CVEs in this product scope (9 CVEs).

Top CNAs Publishing CVEs For X Pack

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
6.2.219.81.6%00
6.2.119.81.6%00
6.2.019.81.6%00
5.6.018.80.8%00
5.5.227.70.7%00
5.5.027.70.7%00
5.4.038.00.8%00
5.3.338.00.8%00
5.3.238.00.8%00
5.3.138.00.8%00
5.3.038.00.8%00
5.2.228.80.9%00
5.2.128.80.9%00
5.2.028.80.9%00
5.1.138.40.9%00
5.1.018.81.0%00
5.0.228.80.9%00
5.0.128.80.9%00
5.0.028.80.9%00