Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hq5w-vrxc-xx2g

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Elastic Enterprise Search before 7.9.0 contain a credential exposure flaw in the App Search interface. If a user is given the �developer� role, they will be able to view the administrator API credentials. These credentials could allow the developer user to conduct operations with the same permissions of the App Search administrator.

Elastic Enterprise Search before 7.9.0 contain a credential exposure flaw in the App Search interface. If a user is given the �developer� role, they will be able to view the administrator API credentials. These credentials could allow the developer user to conduct operations with the same permissions of the App Search administrator.

EPSS

Процентиль: 38%
0.00166
Низкий

Связанные уязвимости

CVSS3: 8.8
ubuntu
больше 5 лет назад

Elastic Enterprise Search before 7.9.0 contain a credential exposure flaw in the App Search interface. If a user is given the �developer� role, they will be able to view the administrator API credentials. These credentials could allow the developer user to conduct operations with the same permissions of the App Search administrator.

CVSS3: 8.8
nvd
больше 5 лет назад

Elastic Enterprise Search before 7.9.0 contain a credential exposure flaw in the App Search interface. If a user is given the �developer� role, they will be able to view the administrator API credentials. These credentials could allow the developer user to conduct operations with the same permissions of the App Search administrator.

CVSS3: 8.8
debian
больше 5 лет назад

Elastic Enterprise Search before 7.9.0 contain a credential exposure f ...

EPSS

Процентиль: 38%
0.00166
Низкий