Elastic Enterprise Search before 7.9.0 contain a credential exposure flaw in the App Search interface. If a user is given the �developer� role, they will be able to view the administrator API credentials. These credentials could allow the developer user to conduct operations with the same permissions of the App Search administrator.
References
Link | Resource |
---|---|
https://discuss.elastic.co/t/enterprise-search-7-9-0-security-update/245457 | Vendor Advisory |
https://discuss.elastic.co/t/enterprise-search-7-9-0-security-update/245457 | Vendor Advisory |
Configurations
History
21 Nov 2024, 05:36
Type | Values Removed | Values Added |
---|---|---|
References | () https://discuss.elastic.co/t/enterprise-search-7-9-0-security-update/245457 - Vendor Advisory |
Information
Published : 2020-08-18 17:15
Updated : 2024-11-21 05:36
NVD link : CVE-2020-7018
Mitre link : CVE-2020-7018
CVE.ORG link : CVE-2020-7018
JSON object : View
Products Affected
elastic
- enterprise_search