ElasticsearchGHSA-cqgv-256r-m9r8
Insertion of Sensitive Information into Log File in Elasticsearch
Medium4.9CVE-2020-7021 · Published May 24, 2022 · updated Feb 21, 2024
Elasticsearch versions before 7.10.0 and 6.8.14 have an information disclosure issue when audit logging and the emit_request_body option is enabled. The Elasticsearch audit log could contain sensitive information such as password hashes or authentication tokens. This could allow an Elasticsearch administrator to view these details.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| org.elasticsearch:elasticsearch Maven | < 6.8.14 | 6.8.14 |
| >= 7.0.0, < 7.10.0 | 7.10.0 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-532
- Also known as
- BIT-elasticsearch-2020-7021, CVE-2020-7021
More Elasticsearch advisories
All Elasticsearch| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| May 242022 | Exposure of Sensitive Information to an Unauthorized Actor in Elasticsearch | Medium5.3 | 6.8.15+1 more |
| May 242022 | Improper privilege management in elasticsearch | Medium6.5 | 6.8.12+1 more |
| May 242022 | Improper Privilege Management in Elasticsearch | High8.8 | 6.8.8+1 more |
| May 242022 | Exposure of Sensitive Information to an Unauthorized Actor in Elasticsearch | Medium5.3 | 6.8.4+1 more |
| May 242022 | Concurrent Execution using Shared Resource with Improper Synchronization in Elasticsearch | Medium5.9 | 6.8.2+1 more |
| May 172022 | Improper Limitation of a Pathname to a Restricted Directory in Elasticsearch | Medium | 1.4.5+1 more |