{"id":"GHSA-ccmr-qj26-845g","summary":"Improper Restriction of XML External Entity Reference in Elasticsearch","details":"Elasticsearch Security versions 6.5.0 and 6.5.1 contain an XXE flaw in Machine Learning's find_file_structure API. If a policy allowing external network access has been added to Elasticsearch's Java Security Manager then an attacker could send a specially crafted request capable of leaking content of local files on the Elasticsearch node. This could allow a user to access information that they should not have access to.","aliases":["CVE-2018-17247"],"modified":"2023-11-08T04:00:03.960932Z","published":"2022-05-13T01:34:04Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2022-06-28T23:22:46Z","nvd_published_at":"2018-12-20T22:29:00Z","cwe_ids":["CWE-611"],"severity":"MODERATE"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2018-17247"},{"type":"WEB","url":"https://discuss.elastic.co/t/elastic-stack-6-5-2-security-update/159594"},{"type":"WEB","url":"https://www.elastic.co/community/security"},{"type":"WEB","url":"http://www.securityfocus.com/bid/106294"}],"affected":[{"package":{"name":"org.elasticsearch:elasticsearch","ecosystem":"Maven","purl":"pkg:maven/org.elasticsearch/elasticsearch"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"6.5.0"},{"fixed":"6.5.2"}]}],"versions":["6.5.0","6.5.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-ccmr-qj26-845g/GHSA-ccmr-qj26-845g.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"}]}