Elastic Enterprise Search before 7.9.0 contain a credential exposure flaw in the App Search interface. If a user is given the �developer� role, they will be able to view the administrator API credentials. These credentials could allow the developer user to conduct operations with the same permissions of the App Search administrator.
References
| Link | Resource |
|---|---|
| https://discuss.elastic.co/t/enterprise-search-7-9-0-security-update/245457 | Vendor Advisory |
| https://discuss.elastic.co/t/enterprise-search-7-9-0-security-update/245457 | Vendor Advisory |
Configurations
History
No history.
Information
Published : 2020-08-18 17:15
Updated : 2024-11-21 05:36
NVD link : CVE-2020-7018
Mitre link : CVE-2020-7018
CVE.ORG link : CVE-2020-7018
JSON object : View
Products Affected
elastic
- enterprise_search
