Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Matt Peel

Researcher fromSilverstripe
#28920of 53,633
8.8Total CVSS
Vulnerabilities · 1
PT-2020-19343
8.8
2020-08-18
Elastic · Vx Search Enterprise · CVE-2020-7018
**Name of the Vulnerable Software and Affected Versions** Elastic Enterprise Search versions prior to 7.9.0 **Description** The issue allows a user with the `developer` role to view the administrator API credentials in the App Search interface. These credentials could enable the developer user to perform operations with the same permissions as the App Search administrator. **Recommendations** For versions prior to 7.9.0, update to version 7.9.0 or later to resolve the issue. As a temporary workaround, consider restricting the `developer` role to minimize the risk of credential exposure.