Vulnerability Description
X-Pack Security versions 6.2.0, 6.2.1, and 6.2.2 are vulnerable to a user impersonation attack via incorrect XML canonicalization and DOM traversal. An attacker might have been able to impersonate a legitimate user if the SAML Identity Provider allows for self registration with arbitrary identifiers and the attacker can register an account which an identifier that shares a suffix with a legitimate account. Both of those conditions must be true in order to exploit this flaw.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Elastic | X-Pack | 6.2.0 |
Related Weaknesses (CWE)
References
- https://discuss.elastic.co/t/elastic-stack-6-2-3-security-update/124848Vendor Advisory
- https://discuss.elastic.co/t/elastic-stack-6-2-3-security-update/124848Vendor Advisory
FAQ
What is CVE-2018-3822?
CVE-2018-3822 is a vulnerability with a CVSS score of 9.8 (CRITICAL). X-Pack Security versions 6.2.0, 6.2.1, and 6.2.2 are vulnerable to a user impersonation attack via incorrect XML canonicalization and DOM traversal. An attacker might have been able to impersonate a l...
How severe is CVE-2018-3822?
CVE-2018-3822 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2018-3822?
Check the references section above for vendor advisories and patch information. Affected products include: Elastic X-Pack.