Skip to content
ElasticsearchGHSA-g9fw-9x87-rmrj

Privilege Context Switching Error in Elasticsearch

Low3.1CVE-2020-7020 · Published Mar 18, 2021 · updated Feb 22, 2024

Elasticsearch versions before 6.8.13 and 7.9.2 contain a document disclosure flaw when Document or Field Level Security is used. Search queries do not properly preserve security permissions when executing certain complex queries. This could result in the search disclosing the existence of documents the attacker should not be able to view. This could result in an attacker gaining additional insight into potentially sensitive indices.

GitHub advisory

Affected versions

PackageAffectedFixed in
org.elasticsearch:elasticsearch
Maven
< 6.8.136.8.13
>= 7.0.0, < 7.9.27.9.2
Details and references

More Elasticsearch advisories

All Elasticsearch
Advisory
Exposure of sensitive information in Elasticsearch
Medium6.5Sep 20, 2021
Denial of Service in Elasticsearch
Medium5.7Aug 9, 2021
API information disclosure flaw in Elasticsearch
Medium5.3Jul 2, 2021
Insufficiently Protected Credentials in Elasticsearch
Medium4.8Mar 18, 2021
Privilege Escalation Flaw in Elasticsearch
Medium8.8Mar 18, 2021
Exposure of Sensitive Information to an Unauthorized Actor
Medium4.3Mar 18, 2021

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.