Added |
CVSS V3 |
|
AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N
|
Added |
CVSS V2 |
|
(AV:N/AC:M/Au:S/C:N/I:P/A:N)
|
Added |
CWE |
|
CWE-79
|
Added |
CPE Configuration |
|
OR
*cpe:2.3:a:elastic:elasticsearch_x-pack:*:*:*:*:*:*:*:* versions up to (excluding) 5.6.9
*cpe:2.3:a:elastic:elasticsearch_x-pack:*:*:*:*:*:*:*:* versions from (including) 6.0.0 up to (excluding) 6.2.4
*cpe:2.3:a:elastic:elasticsearch_x-pack:6.0.0:alpha1:*:*:*:*:*:*
*cpe:2.3:a:elastic:elasticsearch_x-pack:6.0.0:alpha2:*:*:*:*:*:*
*cpe:2.3:a:elastic:elasticsearch_x-pack:6.0.0:beta1:*:*:*:*:*:*
*cpe:2.3:a:elastic:elasticsearch_x-pack:6.0.0:beta2:*:*:*:*:*:*
*cpe:2.3:a:elastic:elasticsearch_x-pack:6.0.0:rc1:*:*:*:*:*:*
*cpe:2.3:a:elastic:elasticsearch_x-pack:6.0.0:rc2:*:*:*:*:*:*
|
Added |
CPE Configuration |
|
OR
*cpe:2.3:a:elastic:kibana_x-pack:*:*:*:*:*:*:*:* versions up to (excluding) 5.6.9
*cpe:2.3:a:elastic:kibana_x-pack:*:*:*:*:*:*:*:* versions from (including) 6.0.0 up to (excluding) 6.2.4
|
Added |
CPE Configuration |
|
OR
*cpe:2.3:a:elastic:logstash_x-pack:*:*:*:*:*:*:*:* versions up to (excluding) 5.6.9
*cpe:2.3:a:elastic:logstash_x-pack:*:*:*:*:*:*:*:* versions from (including) 6.1.0 up to (excluding) 6.2.4
|
Changed |
Reference Type |
https://discuss.elastic.co/t/elastic-stack-6-2-4-and-5-6-9-security-update/128422 No Types Assigned
|
https://discuss.elastic.co/t/elastic-stack-6-2-4-and-5-6-9-security-update/128422 Vendor Advisory
|
Changed |
Reference Type |
https://www.elastic.co/community/security No Types Assigned
|
https://www.elastic.co/community/security Vendor Advisory
|
Added |
CVSS V2 Metadata |
|
Victim must voluntarily interact with attack mechanism
|