CVE-2020-7019
- EPSS 0.14%
- Veröffentlicht 18.08.2020 17:15:11
- Zuletzt bearbeitet 21.11.2024 05:36:30
In Elasticsearch before 7.9.0 and 6.8.12 a field disclosure flaw was found when running a scrolling search with Field Level Security. If a user runs the same query another more privileged user recently ran, the scrolling search can leak fields that s...
CVE-2020-7014
- EPSS 0.57%
- Veröffentlicht 03.06.2020 18:15:23
- Zuletzt bearbeitet 21.11.2024 05:36:29
The fix for CVE-2020-7009 was found to be incomplete. Elasticsearch versions from 6.7.0 to 6.8.7 and 7.0.0 to 7.6.1 contain a privilege escalation flaw if an attacker is able to create API keys and also authentication tokens. An attacker who is able ...
CVE-2020-7009
- EPSS 1.54%
- Veröffentlicht 31.03.2020 19:15:14
- Zuletzt bearbeitet 21.11.2024 05:36:29
Elasticsearch versions from 6.7.0 before 6.8.8 and 7.0.0 before 7.6.2 contain a privilege escalation flaw if an attacker is able to create API keys. An attacker who is able to generate an API key can perform a series of steps that result in an API ke...
CVE-2019-7619
- EPSS 2.16%
- Veröffentlicht 30.10.2019 14:15:11
- Zuletzt bearbeitet 21.11.2024 04:48:24
Elasticsearch versions 7.0.0-7.3.2 and 6.7.0-6.8.3 contain a username disclosure flaw was found in the API Key service. An unauthenticated attacker could send a specially crafted request and determine if a username exists in the Elasticsearch native ...
CVE-2019-7614
- EPSS 0.25%
- Veröffentlicht 30.07.2019 22:15:12
- Zuletzt bearbeitet 21.11.2024 04:48:24
A race condition flaw was found in the response headers Elasticsearch versions before 7.2.1 and 6.8.2 returns to a request. On a system with multiple users submitting requests, it could be possible for an attacker to gain access to response header co...
CVE-2019-7611
- EPSS 0.71%
- Veröffentlicht 25.03.2019 19:29:02
- Zuletzt bearbeitet 21.11.2024 04:48:23
A permission issue was found in Elasticsearch versions before 5.6.15 and 6.6.1 when Field Level Security and Document Level Security are disabled and the _aliases, _shrink, or _split endpoints are used . If the elasticsearch.yml file has xpack.securi...
CVE-2018-17247
- EPSS 0.31%
- Veröffentlicht 20.12.2018 22:29:00
- Zuletzt bearbeitet 21.11.2024 03:54:09
Elasticsearch Security versions 6.5.0 and 6.5.1 contain an XXE flaw in Machine Learning's find_file_structure API. If a policy allowing external network access has been added to Elasticsearch's Java Security Manager then an attacker could send a spec...
CVE-2018-17244
- EPSS 0.9%
- Veröffentlicht 20.12.2018 22:29:00
- Zuletzt bearbeitet 21.11.2024 03:54:09
Elasticsearch Security versions 6.4.0 to 6.4.2 contain an error in the way request headers are applied to requests when using the Active Directory, LDAP, Native, or File realms. A request may receive headers intended for another request if the same u...
CVE-2018-3831
- EPSS 0.86%
- Veröffentlicht 19.09.2018 19:29:01
- Zuletzt bearbeitet 21.11.2024 04:06:07
Elasticsearch Alerting and Monitoring in versions before 6.4.1 or 5.6.12 have an information disclosure issue when secrets are configured via the API. The Elasticsearch _cluster/settings API, when queried, could leak sensitive configuration informati...
CVE-2018-3826
- EPSS 0.4%
- Veröffentlicht 19.09.2018 19:29:00
- Zuletzt bearbeitet 21.11.2024 04:06:06
In Elasticsearch versions 6.0.0-beta1 to 6.2.4 a disclosure flaw was found in the _snapshot API. When the access_key and security_key parameters are set using the _snapshot API they can be exposed as plain text by users able to query the _snapshot AP...