Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-7614

Опубликовано: 30 июл. 2019
Источник: nvd
CVSS3: 5.9
CVSS2: 4.3
EPSS Низкий

Описание

A race condition flaw was found in the response headers Elasticsearch versions before 7.2.1 and 6.8.2 returns to a request. On a system with multiple users submitting requests, it could be possible for an attacker to gain access to response header containing sensitive data from another user.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:elastic:elasticsearch:*:*:*:*:*:*:*:*
Версия до 6.8.2 (исключая)
cpe:2.3:a:elastic:elasticsearch:*:*:*:*:*:*:*:*
Версия от 7.0.0 (включая) до 7.2.1 (исключая)

EPSS

Процентиль: 48%
0.00247
Низкий

5.9 Medium

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-362
CWE-362

Связанные уязвимости

CVSS3: 5.9
ubuntu
больше 6 лет назад

A race condition flaw was found in the response headers Elasticsearch versions before 7.2.1 and 6.8.2 returns to a request. On a system with multiple users submitting requests, it could be possible for an attacker to gain access to response header containing sensitive data from another user.

CVSS3: 2
redhat
больше 6 лет назад

A race condition flaw was found in the response headers Elasticsearch versions before 7.2.1 and 6.8.2 returns to a request. On a system with multiple users submitting requests, it could be possible for an attacker to gain access to response header containing sensitive data from another user.

CVSS3: 5.9
debian
больше 6 лет назад

A race condition flaw was found in the response headers Elasticsearch ...

CVSS3: 5.9
github
больше 3 лет назад

Concurrent Execution using Shared Resource with Improper Synchronization in Elasticsearch

EPSS

Процентиль: 48%
0.00247
Низкий

5.9 Medium

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-362
CWE-362