CVE-2017-12195
published 2018-07-27CVE-2017-12195: A flaw was found in all Openshift Enterprise versions using the openshift elasticsearch plugin. An attacker with knowledge of the given name used to…
PriorityP428medium4.8CVSS 3.0
AVNACHPRNUINSUCLILAN
EPSS
1.40%
69.4th percentile
A flaw was found in all Openshift Enterprise versions using the openshift elasticsearch plugin. An attacker with knowledge of the given name used to authenticate and access Elasticsearch can later access it without the token, bypassing authentication. This attack also requires that the Elasticsearch be configured with an external route, and the data accessed is limited to the indices.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| red_hat | openshift | — | — |
| redhat | openshift_container_platform | — | — |
| redhat | openshift_container_platform | — | — |
| redhat | openshift_container_platform | — | — |
| redhat | openshift_container_platform | — | — |
CVSS provenance
nvdv3.04.8MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
3: authentication bypass for elasticsearch with external routes
vendor_redhat·2017-11-28·CVSS 6.5
CVE-2017-12195 [MEDIUM] CWE-287 3: authentication bypass for elasticsearch with external routes
3: authentication bypass for elasticsearch with external routes
A flaw was found in all Openshift Enterprise versions using the openshift elasticsearch plugin. An attacker with knowledge of the given name used to authenticate and access Elasticsearch can later access it without the token, bypassing authentication. This attack also requires that the Elasticsearch be configured with an external route, and the data accessed is limited to the indices.
An attacker with knowledge of the given name used to authenticate and access Elasticsearch can later access it without the token, bypassing authentication. This attack also requires that the Elasticsearch be configured with an external route, and the data accessed is limited to the indices.
GHSA
GHSA-f727-j88g-p3m8: A flaw was found in all Openshift Enterprise versions using the openshift elasticsearch plugin
ghsa_unreviewed·2022-05-13
CVE-2017-12195 [MEDIUM] CWE-287 GHSA-f727-j88g-p3m8: A flaw was found in all Openshift Enterprise versions using the openshift elasticsearch plugin
A flaw was found in all Openshift Enterprise versions using the openshift elasticsearch plugin. An attacker with knowledge of the given name used to authenticate and access Elasticsearch can later access it without the token, bypassing authentication. This attack also requires that the Elasticsearch be configured with an external route, and the data accessed is limited to the indices.
No detection rules found.
No public exploits indexed.
https://access.redhat.com/errata/RHSA-2017:3188https://access.redhat.com/errata/RHSA-2017:3389https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-12195https://access.redhat.com/errata/RHSA-2017:3188https://access.redhat.com/errata/RHSA-2017:3389https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-12195
2018-07-27
Published