Vigil@nce - Elasticsearch: information disclosure
May 2017 by Marc Jacob
This bulletin was written by Vigil@nce : https://vigilance.fr/offer
SYNTHESIS OF THE VULNERABILITY
An attacker can bypass access restrictions to indices of
Elasticsearch when at least two access rule sets are merged, in
order to get sensitive information.
Impacted products: Elasticsearch.
Severity: 2/4.
Creation date: 29/03/2017.
DESCRIPTION OF THE VULNERABILITY
An attacker can bypass access restrictions to indices of
Elasticsearch when at least two access rule sets are merged, in
order to get sensitive information.
Technical details are unknown.
ACCESS TO THE COMPLETE VIGIL@NCE BULLETIN
https://vigilance.fr/vulnerability/Elasticsearch-information-disclosure-22286