Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2019-7614

Опубликовано: 30 июл. 2019
Источник: debian
EPSS Низкий

Описание

A race condition flaw was found in the response headers Elasticsearch versions before 7.2.1 and 6.8.2 returns to a request. On a system with multiple users submitting requests, it could be possible for an attacker to gain access to response header containing sensitive data from another user.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
elasticsearchremovedpackage

EPSS

Процентиль: 48%
0.00247
Низкий

Связанные уязвимости

CVSS3: 5.9
ubuntu
больше 6 лет назад

A race condition flaw was found in the response headers Elasticsearch versions before 7.2.1 and 6.8.2 returns to a request. On a system with multiple users submitting requests, it could be possible for an attacker to gain access to response header containing sensitive data from another user.

CVSS3: 2
redhat
больше 6 лет назад

A race condition flaw was found in the response headers Elasticsearch versions before 7.2.1 and 6.8.2 returns to a request. On a system with multiple users submitting requests, it could be possible for an attacker to gain access to response header containing sensitive data from another user.

CVSS3: 5.9
nvd
больше 6 лет назад

A race condition flaw was found in the response headers Elasticsearch versions before 7.2.1 and 6.8.2 returns to a request. On a system with multiple users submitting requests, it could be possible for an attacker to gain access to response header containing sensitive data from another user.

CVSS3: 5.9
github
больше 3 лет назад

Concurrent Execution using Shared Resource with Improper Synchronization in Elasticsearch

EPSS

Процентиль: 48%
0.00247
Низкий