PT-2021-12634 · Elastic · Elasticsearch

Published

2021-02-10

·

Updated

2024-03-06

·

CVE-2020-7021

CVSS v3.1

4.9

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Elasticsearch versions prior to 7.10.0 Elasticsearch versions prior to 6.8.14
Description: The issue is related to an information disclosure problem when audit logging and the emit request body option are enabled. This could lead to the Elasticsearch audit log containing sensitive information, such as password hashes or authentication tokens, allowing an Elasticsearch administrator to view these details.
Recommendations: For Elasticsearch versions prior to 7.10.0, update to version 7.10.0 or later to resolve the issue. For Elasticsearch versions prior to 6.8.14, update to version 6.8.14 or later to resolve the issue. As a temporary workaround, consider disabling the emit request body option to prevent sensitive information from being logged until a patch is applied.

Fix

Insertion into Log File

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-ELASTICSEARCH-2020-7021
CVE-2020-7021
GHSA-CQGV-256R-M9R8

Affected Products

Elasticsearch