XXE attack in Elasticsearch - CVE-2018-17247
Published: December 19, 2018
Elasticsearch
Detailed vulnerability description
The vulnerability exists in Machine Learning’s find_file_structure API due to improper handling of XML External Entities (XXEs) when parsing an XML file if a policy allowing external network access has been added to Elasticsearch’s Java Security Manager. A remote attacker can trick the victim into opening an XML file that submits malicious input and obtain potentially sensitive information.