Skip to content

Conversation

@droberts195
Copy link

Now that ML configurations are stored in the .ml-config
index rather than in cluster state there is a possibility
that some users may try to add configurations directly to
the index. Allowing this creates a variety of problems
including possible data exflitration attacks (depending on
how security is set up), so this commit adds warnings
against allowing writes to the .ml-config index other than
via the ML APIs.

Backport of #38509

Now that ML configurations are stored in the .ml-config
index rather than in cluster state there is a possibility
that some users may try to add configurations directly to
the index.  Allowing this creates a variety of problems
including possible data exflitration attacks (depending on
how security is set up), so this commit adds warnings
against allowing writes to the .ml-config index other than
via the ML APIs.

Backport of elastic#38509
@droberts195 droberts195 added >docs General docs changes :ml Machine learning backport labels Feb 8, 2019
@elasticmachine
Copy link
Collaborator

Pinging @elastic/ml-core

@droberts195 droberts195 merged commit 869843b into elastic:6.7 Feb 8, 2019
@droberts195 droberts195 deleted the add_config_index_warning_67 branch February 8, 2019 11:36
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

backport >docs General docs changes :ml Machine learning

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants