CVE-2018-3822
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
X-Pack Security versions 6.2.0, 6.2.1, and 6.2.2 are vulnerable to a user impersonation attack via incorrect XML canonicalization and DOM traversal. An attacker might have been able to impersonate a legitimate user if the SAML Identity Provider allows for self registration with arbitrary identifiers and the attacker can register an account which an identifier that shares a suffix with a legitimate account. Both of those conditions must be true in order to exploit this flaw.
X-Pack Security en versiones 6.2.0, 6.2.1 y 6.2.2 son vulnerables a un ataque de suplantación de usuario mediante una canonización XML incorrecta y un salto de DOM. Un atacante podría suplantar la identidad de un usuario legítimo si el proveedor de identidades SAML permite el autorregistro con identificadores arbitrarios y el atacante puede registrar una cuenta con un identificador que comparte un sufijo con una cuenta legítima. Ambas condiciones deben ser verdaderas para explotar esta vulnerabilidad.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2018-01-02 CVE Reserved
- 2018-03-30 CVE Published
- 2024-03-09 EPSS Updated
- 2024-08-05 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
- CWE-287: Improper Authentication
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://discuss.elastic.co/t/elastic-stack-6-2-3-security-update/124848 | 2023-03-24 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Elastic Search vendor "Elastic" | X-pack Search vendor "Elastic" for product "X-pack" | 6.2.0 Search vendor "Elastic" for product "X-pack" and version "6.2.0" | - |
Affected
| ||||||
Elastic Search vendor "Elastic" | X-pack Search vendor "Elastic" for product "X-pack" | 6.2.1 Search vendor "Elastic" for product "X-pack" and version "6.2.1" | - |
Affected
| ||||||
Elastic Search vendor "Elastic" | X-pack Search vendor "Elastic" for product "X-pack" | 6.2.2 Search vendor "Elastic" for product "X-pack" and version "6.2.2" | - |
Affected
|