PT-2019-18666 · Elastic · Elasticsearch
Published
2019-07-30
·
Updated
2023-03-03
·
CVE-2019-7614
CVSS v3.1
5.9
Medium
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Elasticsearch versions prior to 7.2.1
Elasticsearch versions prior to 6.8.2
Description
A race condition flaw was found in the response headers returned by Elasticsearch. On a system with multiple users submitting requests, it could be possible for an attacker to gain access to response headers containing sensitive data from another user.
Recommendations
For Elasticsearch versions prior to 7.2.1, update to version 7.2.1 or later to resolve the issue.
For Elasticsearch versions prior to 6.8.2, update to version 6.8.2 or later to resolve the issue.
Fix
Race Condition
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Elasticsearch