Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jqm6-m3j3-8gg9

Опубликовано: 24 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 5.9

Описание

Concurrent Execution using Shared Resource with Improper Synchronization in Elasticsearch

A race condition flaw was found in the response headers Elasticsearch versions before 7.2.1 and 6.8.2 returns to a request. On a system with multiple users submitting requests, it could be possible for an attacker to gain access to response header containing sensitive data from another user.

Пакеты

Наименование

org.elasticsearch:elasticsearch

maven
Затронутые версииВерсия исправления

< 6.8.2

6.8.2

Наименование

org.elasticsearch:elasticsearch

maven
Затронутые версииВерсия исправления

>= 7.0.0, < 7.2.1

7.2.1

EPSS

Процентиль: 48%
0.00247
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-362

Связанные уязвимости

CVSS3: 5.9
ubuntu
больше 6 лет назад

A race condition flaw was found in the response headers Elasticsearch versions before 7.2.1 and 6.8.2 returns to a request. On a system with multiple users submitting requests, it could be possible for an attacker to gain access to response header containing sensitive data from another user.

CVSS3: 2
redhat
больше 6 лет назад

A race condition flaw was found in the response headers Elasticsearch versions before 7.2.1 and 6.8.2 returns to a request. On a system with multiple users submitting requests, it could be possible for an attacker to gain access to response header containing sensitive data from another user.

CVSS3: 5.9
nvd
больше 6 лет назад

A race condition flaw was found in the response headers Elasticsearch versions before 7.2.1 and 6.8.2 returns to a request. On a system with multiple users submitting requests, it could be possible for an attacker to gain access to response header containing sensitive data from another user.

CVSS3: 5.9
debian
больше 6 лет назад

A race condition flaw was found in the response headers Elasticsearch ...

EPSS

Процентиль: 48%
0.00247
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-362