Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2020-7018

Опубликовано: 18 авг. 2020
Источник: debian
EPSS Низкий

Описание

Elastic Enterprise Search before 7.9.0 contain a credential exposure flaw in the App Search interface. If a user is given the �developer� role, they will be able to view the administrator API credentials. These credentials could allow the developer user to conduct operations with the same permissions of the App Search administrator.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
elasticsearchremovedpackage

EPSS

Процентиль: 38%
0.00166
Низкий

Связанные уязвимости

CVSS3: 8.8
ubuntu
больше 5 лет назад

Elastic Enterprise Search before 7.9.0 contain a credential exposure flaw in the App Search interface. If a user is given the �developer� role, they will be able to view the administrator API credentials. These credentials could allow the developer user to conduct operations with the same permissions of the App Search administrator.

CVSS3: 8.8
nvd
больше 5 лет назад

Elastic Enterprise Search before 7.9.0 contain a credential exposure flaw in the App Search interface. If a user is given the �developer� role, they will be able to view the administrator API credentials. These credentials could allow the developer user to conduct operations with the same permissions of the App Search administrator.

github
больше 3 лет назад

Elastic Enterprise Search before 7.9.0 contain a credential exposure flaw in the App Search interface. If a user is given the �developer� role, they will be able to view the administrator API credentials. These credentials could allow the developer user to conduct operations with the same permissions of the App Search administrator.

EPSS

Процентиль: 38%
0.00166
Низкий