PT-2021-12634 · Elastic · Elasticsearch
Published
2021-02-10
·
Updated
2024-03-06
·
CVE-2020-7021
CVSS v3.1
4.9
Medium
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
Elasticsearch versions prior to 7.10.0
Elasticsearch versions prior to 6.8.14
Description:
The issue is related to an information disclosure problem when audit logging and the
emit request body option are enabled. This could lead to the Elasticsearch audit log containing sensitive information, such as password hashes or authentication tokens, allowing an Elasticsearch administrator to view these details.Recommendations:
For Elasticsearch versions prior to 7.10.0, update to version 7.10.0 or later to resolve the issue.
For Elasticsearch versions prior to 6.8.14, update to version 6.8.14 or later to resolve the issue.
As a temporary workaround, consider disabling the
emit request body option to prevent sensitive information from being logged until a patch is applied.Fix
Insertion into Log File
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Elasticsearch