ElasticsearchGHSA-c77j-p484-h84m
Improper privilege management in elasticsearch
Medium6.5CVE-2020-7019 · Published May 24, 2022 · updated Feb 19, 2024
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| org.elasticsearch:elasticsearch Maven | >= 7.0.0, < 7.9.0 | 7.9.0 |
| < 6.8.12 | 6.8.12 |
Details and references
In Elasticsearch before 7.9.0 and 6.8.12 a field disclosure flaw was found when running a scrolling search with Field Level Security. If a user runs the same query another more privileged user recently ran, the scrolling search can leak fields that should be hidden. This could result in an attacker gaining additional permissions against a restricted index.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-269
- Also known as
- BIT-elasticsearch-2020-7019, CVE-2020-7019
More Elasticsearch advisories
All Elasticsearch| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| May 242022 | Concurrent Execution using Shared Resource with Improper Synchronization in Elasticsearch CVE-2019-7614Medium5.9fixed in 6.8.2, 7.2.1 | Medium5.9 | 6.8.2, 7.2.1 |
| May 242022 | Exposure of Sensitive Information to an Unauthorized Actor in Elasticsearch CVE-2019-7619Medium5.3fixed in 6.8.4, 7.4.0 | Medium5.3 | 6.8.4, 7.4.0 |
| May 242022 | Improper Privilege Management in Elasticsearch CVE-2020-7009High8.8fixed in 6.8.8, 7.6.2 | High8.8 | 6.8.8, 7.6.2 |
| May 242022 | Insertion of Sensitive Information into Log File in Elasticsearch CVE-2020-7021Medium4.9fixed in 6.8.14, 7.10.0 | Medium4.9 | 6.8.14, 7.10.0 |
| May 242022 | Exposure of Sensitive Information to an Unauthorized Actor in Elasticsearch CVE-2021-22137Medium5.3fixed in 6.8.15, 7.11.2 | Medium5.3 | 6.8.15, 7.11.2 |
| May 172022 | Improper Limitation of a Pathname to a Restricted Directory in Elasticsearch CVE-2015-3337Mediumfixed in 1.4.5, 1.5.2 | Medium | 1.4.5, 1.5.2 |