PT-2020-19344 · Elastic · Elasticsearch
Published
2020-08-18
·
Updated
2024-03-06
·
CVE-2020-7019
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Elasticsearch versions prior to 7.9.0
Elasticsearch versions prior to 6.8.12
Description
A field disclosure flaw was found in Elasticsearch when running a scrolling search with Field Level Security. If a user runs the same query another more privileged user recently ran, the scrolling search can leak fields that should be hidden, potentially allowing an attacker to gain additional permissions against a restricted index.
Recommendations
For versions prior to 7.9.0, update to version 7.9.0 or later to resolve the issue.
For versions prior to 6.8.12, update to version 6.8.12 or later to resolve the issue.
Fix
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Elasticsearch