Improper neutralization of special elements used in a template engine in Elastic Cloud Enterprise (ECE) can lead to a malicious actor with Admin access exfiltrating sensitive information and issuing commands via a specially crafted string where Jinjava variables are evaluated.
| Software | From | Fixed in |
|---|---|---|
| elastic / elastic_cloud_enterprise | 2.5.0 | 3.8.2 |
| elastic / elastic_cloud_enterprise | 4.0.0 | 4.0.2 |