SB2018121901 - XXE attack in Elasticsearch
Published: December 19, 2018
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) XXE attack (CVE-ID: CVE-2018-17247)
The vulnerability allows a remote attacker to conduct XXE-attack.
The vulnerability exists in Machine Learning’s find_file_structure API due to improper handling of XML External Entities (XXEs) when parsing an XML file if a policy allowing external network access has been added to Elasticsearch’s Java Security Manager. A remote attacker can trick the victim into opening an XML file that submits malicious input and obtain potentially sensitive information.
Remediation
Install update from vendor's website.