PT-2020-19343 · Elastic · Vx Search Enterprise

Matt Peel

·

Published

2020-08-18

·

Updated

2020-08-26

·

CVE-2020-7018

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Elastic Enterprise Search versions prior to 7.9.0
Description The issue allows a user with the developer role to view the administrator API credentials in the App Search interface. These credentials could enable the developer user to perform operations with the same permissions as the App Search administrator.
Recommendations For versions prior to 7.9.0, update to version 7.9.0 or later to resolve the issue. As a temporary workaround, consider restricting the developer role to minimize the risk of credential exposure.

Fix

Incorrect Privilege Assignment

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-7018

Affected Products

Vx Search Enterprise