Skip to content
ElasticsearchGHSA-c77j-p484-h84m

Improper privilege management in elasticsearch

Medium6.5CVE-2020-7019 · Published May 24, 2022 · updated Feb 19, 2024

GitHub advisory

Affected versions

PackageAffectedFixed in
org.elasticsearch:elasticsearch
Maven
>= 7.0.0, < 7.9.07.9.0
< 6.8.126.8.12
Details and references

In Elasticsearch before 7.9.0 and 6.8.12 a field disclosure flaw was found when running a scrolling search with Field Level Security. If a user runs the same query another more privileged user recently ran, the scrolling search can leak fields that should be hidden. This could result in an attacker gaining additional permissions against a restricted index.

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-269
Also known as
BIT-elasticsearch-2020-7019, CVE-2020-7019

More Elasticsearch advisories

All Elasticsearch
DateAdvisory
May 242022Concurrent Execution using Shared Resource with Improper Synchronization in Elasticsearch
CVE-2019-7614Medium5.9fixed in 6.8.2, 7.2.1
May 242022Exposure of Sensitive Information to an Unauthorized Actor in Elasticsearch
CVE-2019-7619Medium5.3fixed in 6.8.4, 7.4.0
May 242022Improper Privilege Management in Elasticsearch
CVE-2020-7009High8.8fixed in 6.8.8, 7.6.2
May 242022Insertion of Sensitive Information into Log File in Elasticsearch
CVE-2020-7021Medium4.9fixed in 6.8.14, 7.10.0
May 242022Exposure of Sensitive Information to an Unauthorized Actor in Elasticsearch
CVE-2021-22137Medium5.3fixed in 6.8.15, 7.11.2
May 172022Improper Limitation of a Pathname to a Restricted Directory in Elasticsearch
CVE-2015-3337Mediumfixed in 1.4.5, 1.5.2

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.