Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-45h5-r968-5xr7

Опубликовано: 20 сент. 2021
Источник: github
Github: Прошло ревью
CVSS3: 6.5

Описание

Exposure of sensitive information in Elasticsearch

A flaw was discovered in Elasticsearch where document and field level security was not applied to searchable snapshots. This could lead to an authenticated user gaining access to information that they are unauthorized to view.

Пакеты

Наименование

org.elasticsearch:elasticsearch

maven
Затронутые версииВерсия исправления

>= 7.11.0, < 7.14.0

7.14.0

EPSS

Процентиль: 54%
0.00314
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-732
CWE-862

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 4 лет назад

Elasticsearch before 7.14.0 did not apply document and field level security to searchable snapshots. This could lead to an authenticated user gaining access to information that they are unauthorized to view.

CVSS3: 5.7
redhat
больше 4 лет назад

Elasticsearch before 7.14.0 did not apply document and field level security to searchable snapshots. This could lead to an authenticated user gaining access to information that they are unauthorized to view.

CVSS3: 6.5
nvd
больше 4 лет назад

Elasticsearch before 7.14.0 did not apply document and field level security to searchable snapshots. This could lead to an authenticated user gaining access to information that they are unauthorized to view.

CVSS3: 6.5
debian
больше 4 лет назад

Elasticsearch before 7.14.0 did not apply document and field level sec ...

EPSS

Процентиль: 54%
0.00314
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-732
CWE-862