CVE-2018-17247: Elastic Elasticsearch
Medium severity, CVSS 5.9. EPSS: 1.4% chance of exploitation in the next 30 days.
Elasticsearch Security versions 6.5.0 and 6.5.1 contain an XXE flaw in Machine Learning's find_file_structure API. If a policy allowing external network access has been added to Elasticsearch's Java Security Manager then an attacker could send a specially crafted request capable of leaking content of local files on the Elasticsearch node. This could allow a user to access information that they should not have access to.
Affected products
- Elastic Elasticsearch: version 6.5.0 only; version 6.5.1 only
Published 2018-12-20. Last modified 2026-06-17.