PT-2020-19344 · Elastic · Elasticsearch

Published

2020-08-18

·

Updated

2024-03-06

·

CVE-2020-7019

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Elasticsearch versions prior to 7.9.0 Elasticsearch versions prior to 6.8.12
Description A field disclosure flaw was found in Elasticsearch when running a scrolling search with Field Level Security. If a user runs the same query another more privileged user recently ran, the scrolling search can leak fields that should be hidden, potentially allowing an attacker to gain additional permissions against a restricted index.
Recommendations For versions prior to 7.9.0, update to version 7.9.0 or later to resolve the issue. For versions prior to 6.8.12, update to version 6.8.12 or later to resolve the issue.

Fix

Improper Privilege Management

Weakness Enumeration

Related Identifiers

BIT-ELASTICSEARCH-2020-7019
CVE-2020-7019
GHSA-C77J-P484-H84M

Affected Products

Elasticsearch