CVE-2017-8449: Elastic X-Pack
Medium severity, CVSS 5.9. EPSS: 0.8% chance of exploitation in the next 30 days.
X-Pack Security 5.2.x would allow access to more fields than the user should have seen if the field level security rules used a mix of grant and exclude rules when merging multiple rules with field level security rules for the same index.
Affected products
- Elastic X-Pack: from 5.2.0, up to and including 5.2.2
Published 2017-06-16. Last modified 2026-06-17.