Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-7619

Опубликовано: 23 окт. 2019
Источник: redhat
CVSS3: 3.7
EPSS Низкий

Описание

Elasticsearch versions 7.0.0-7.3.2 and 6.7.0-6.8.3 contain a username disclosure flaw was found in the API Key service. An unauthenticated attacker could send a specially crafted request and determine if a username exists in the Elasticsearch native realm.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Decision Manager 7elasticsearchNot affected
Red Hat Fuse 7elasticsearchNot affected
Red Hat JBoss Fuse 6elasticsearchOut of support scope
Red Hat OpenShift Container Platform 3.10elasticsearchNot affected
Red Hat OpenShift Container Platform 3.11openshift3/ose-logging-elasticsearch5Not affected
Red Hat OpenShift Container Platform 3.2elasticsearchNot affected
Red Hat OpenShift Container Platform 3.3elasticsearchNot affected
Red Hat OpenShift Container Platform 3.4elasticsearchNot affected
Red Hat OpenShift Container Platform 3.5elasticsearchNot affected
Red Hat OpenShift Container Platform 3.6elasticsearchNot affected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-200
https://bugzilla.redhat.com/show_bug.cgi?id=1764751elasticsearch: Username disclosure in API Key service

EPSS

Процентиль: 81%
0.01601
Низкий

3.7 Low

CVSS3

Связанные уязвимости

CVSS3: 5.3
ubuntu
больше 6 лет назад

Elasticsearch versions 7.0.0-7.3.2 and 6.7.0-6.8.3 contain a username disclosure flaw was found in the API Key service. An unauthenticated attacker could send a specially crafted request and determine if a username exists in the Elasticsearch native realm.

CVSS3: 5.3
nvd
больше 6 лет назад

Elasticsearch versions 7.0.0-7.3.2 and 6.7.0-6.8.3 contain a username disclosure flaw was found in the API Key service. An unauthenticated attacker could send a specially crafted request and determine if a username exists in the Elasticsearch native realm.

CVSS3: 5.3
debian
больше 6 лет назад

Elasticsearch versions 7.0.0-7.3.2 and 6.7.0-6.8.3 contain a username ...

CVSS3: 5.3
github
больше 3 лет назад

Exposure of Sensitive Information to an Unauthorized Actor in Elasticsearch

EPSS

Процентиль: 81%
0.01601
Низкий

3.7 Low

CVSS3