### [CVE-2017-8446](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-8446) ![](https://img.shields.io/static/v1?label=Product&message=Elastic%20X-Pack%20Reporting&color=blue) ![](https://img.shields.io/static/v1?label=Version&message=n%2Fa&color=blue) ![](https://img.shields.io/static/v1?label=Vulnerability&message=CWE-522%3A%20Insufficiently%20Protected%20Credentials&color=brighgreen) ### Description The Reporting feature in X-Pack in versions prior to 5.5.2 and standalone Reporting plugin versions versions prior to 2.4.6 had an impersonation vulnerability. A user with the reporting_user role could execute a report with the permissions of another reporting user, possibly gaining access to sensitive data. ### POC #### Reference - https://www.elastic.co/community/security #### Github No PoCs found on GitHub currently.