CVE-2018-17247: Elastic Elasticsearch

Medium severity, CVSS 5.9. EPSS: 1.4% chance of exploitation in the next 30 days.

Elasticsearch Security versions 6.5.0 and 6.5.1 contain an XXE flaw in Machine Learning's find_file_structure API. If a policy allowing external network access has been added to Elasticsearch's Java Security Manager then an attacker could send a specially crafted request capable of leaking content of local files on the Elasticsearch node. This could allow a user to access information that they should not have access to.

Affected products

  • Elastic Elasticsearch: version 6.5.0 only; version 6.5.1 only

Published 2018-12-20. Last modified 2026-06-17.