Missing Authorization (CWE-862) in the Elasticsearch custom inference service can lead to information disclosure via Privilege Abuse (CAPEC-122). A user holding only inference execution privileges could cause outbound inference traffic to be directed to a destination of their choosing and could cause administrator-provisioned credentials to be exposed.
Attack Parameters
Impact Assessment
CVSS Vector v3.1
Weakness Type (CWE)
Vulnerable Products 4
| Configuration | From (including) | Up to (excluding) |
|---|---|---|
|
Elastic Elasticsearch
cpe:2.3:a:elastic:elasticsearch:*:*:*:*:*:*:*:*
|
8.0.0
|
8.19.19
|
|
Elastic Elasticsearch
cpe:2.3:a:elastic:elasticsearch:*:*:*:*:*:*:*:*
|
9.0.0
|
9.3.8
|
|
Elastic Elasticsearch
cpe:2.3:a:elastic:elasticsearch:*:*:*:*:*:*:*:*
|
9.4.0
|
9.4.4
|
|
Elastic Elasticsearch
cpe:2.3:a:elastic:elasticsearch:9.5.0:*:*:*:*:*:*:*
|
— | — |