Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-7619

Опубликовано: 30 окт. 2019
Источник: nvd
CVSS3: 5.3
CVSS2: 5
EPSS Низкий

Описание

Elasticsearch versions 7.0.0-7.3.2 and 6.7.0-6.8.3 contain a username disclosure flaw was found in the API Key service. An unauthenticated attacker could send a specially crafted request and determine if a username exists in the Elasticsearch native realm.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:elastic:elasticsearch:*:*:*:*:*:*:*:*
Версия от 6.7.0 (включая) до 6.8.3 (включая)
cpe:2.3:a:elastic:elasticsearch:*:*:*:*:*:*:*:*
Версия от 7.0.0 (включая) до 7.3.2 (включая)

EPSS

Процентиль: 81%
0.01601
Низкий

5.3 Medium

CVSS3

5 Medium

CVSS2

Дефекты

CWE-200
NVD-CWE-noinfo

Связанные уязвимости

CVSS3: 5.3
ubuntu
больше 6 лет назад

Elasticsearch versions 7.0.0-7.3.2 and 6.7.0-6.8.3 contain a username disclosure flaw was found in the API Key service. An unauthenticated attacker could send a specially crafted request and determine if a username exists in the Elasticsearch native realm.

CVSS3: 3.7
redhat
больше 6 лет назад

Elasticsearch versions 7.0.0-7.3.2 and 6.7.0-6.8.3 contain a username disclosure flaw was found in the API Key service. An unauthenticated attacker could send a specially crafted request and determine if a username exists in the Elasticsearch native realm.

CVSS3: 5.3
debian
больше 6 лет назад

Elasticsearch versions 7.0.0-7.3.2 and 6.7.0-6.8.3 contain a username ...

CVSS3: 5.3
github
больше 3 лет назад

Exposure of Sensitive Information to an Unauthorized Actor in Elasticsearch

EPSS

Процентиль: 81%
0.01601
Низкий

5.3 Medium

CVSS3

5 Medium

CVSS2

Дефекты

CWE-200
NVD-CWE-noinfo