Overview
- Description
- X-Pack Security versions 6.2.0, 6.2.1, and 6.2.2 are vulnerable to a user impersonation attack via incorrect XML canonicalization and DOM traversal. An attacker might have been able to impersonate a legitimate user if the SAML Identity Provider allows for self registration with arbitrary identifiers and the attacker can register an account which an identifier that shares a suffix with a legitimate account. Both of those conditions must be true in order to exploit this flaw.
- Source
- bressers@elastic.co
- NVD status
- Modified
Risk scores
CVSS 3.1
- Type
- Primary
- Base score
- 9.8
- Impact score
- 5.9
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity
- CRITICAL
CVSS 2.0
- Type
- Primary
- Base score
- 7.5
- Impact score
- 6.4
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:P/I:P/A:P
Social media
- Hype score
- Not currently trending
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:elastic:x-pack:6.2.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2A8D9F28-3341-412B-8957-A946AF1FA384" }, { "criteria": "cpe:2.3:a:elastic:x-pack:6.2.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "EA4A9E6F-3D7D-450D-ADAA-31B8AD0C78CA" }, { "criteria": "cpe:2.3:a:elastic:x-pack:6.2.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C16ABC3F-900B-442D-BD0A-D916418E7CB7" } ], "operator": "OR" } ] } ]