Cross-Site Scripting Vulnerability in X-Pack Machine Learning by Elastic
CVE-2018-3823
Key Information:
- Vendor
Elastic
- Vendor
- CVE Published:
- 19 September 2018
What is CVE-2018-3823?
X-Pack Machine Learning prior to versions 6.2.4 and 5.6.9 is susceptible to a Cross-Site Scripting vulnerability. This issue enables users with manage_ml permissions to craft jobs that include harmful data within their configurations. As a result, an attacker could exploit this vulnerability to gather sensitive information or execute destructive actions unknowingly on behalf of other users who view the job results. It is crucial for users of these affected versions to upgrade to protect against potential threats.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Elasticsearch X-Pack Machine Learning before 6.2.4 and 5.6.9
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved