PT-2020-19343 · Elastic · Vx Search Enterprise
Matt Peel
·
Published
2020-08-18
·
Updated
2020-08-26
·
CVE-2020-7018
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Elastic Enterprise Search versions prior to 7.9.0
Description
The issue allows a user with the
developer role to view the administrator API credentials in the App Search interface. These credentials could enable the developer user to perform operations with the same permissions as the App Search administrator.Recommendations
For versions prior to 7.9.0, update to version 7.9.0 or later to resolve the issue. As a temporary workaround, consider restricting the
developer role to minimize the risk of credential exposure.Fix
Incorrect Privilege Assignment
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Vx Search Enterprise