Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2020-7020

Опубликовано: 22 окт. 2020
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 3.5
CVSS3: 3.1

Описание

Elasticsearch versions before 6.8.13 and 7.9.2 contain a document disclosure flaw when Document or Field Level Security is used. Search queries do not properly preserve security permissions when executing certain complex queries. This could result in the search disclosing the existence of documents the attacker should not be able to view. This could result in an attacker gaining additional insight into potentially sensitive indices.

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-apps-legacy/xenial

needed

esm-apps/xenial

ignored

end of ESM support, was needed
esm-infra-legacy/trusty

DNE

esm-infra/focal

DNE

focal

DNE

groovy

DNE

hirsute

DNE

impish

DNE

Показывать по

EPSS

Процентиль: 60%
0.01011
Низкий

3.5 Low

CVSS2

3.1 Low

CVSS3

Связанные уязвимости

CVSS3: 3.1
redhat
почти 6 лет назад

Elasticsearch versions before 6.8.13 and 7.9.2 contain a document disclosure flaw when Document or Field Level Security is used. Search queries do not properly preserve security permissions when executing certain complex queries. This could result in the search disclosing the existence of documents the attacker should not be able to view. This could result in an attacker gaining additional insight into potentially sensitive indices.

CVSS3: 3.1
nvd
почти 6 лет назад

Elasticsearch versions before 6.8.13 and 7.9.2 contain a document disclosure flaw when Document or Field Level Security is used. Search queries do not properly preserve security permissions when executing certain complex queries. This could result in the search disclosing the existence of documents the attacker should not be able to view. This could result in an attacker gaining additional insight into potentially sensitive indices.

CVSS3: 3.1
msrc
больше 4 лет назад

Elasticsearch versions before 6.8.13 and 7.9.2 contain a document disclosure flaw when Document or Field Level Security is used. Search queries do not properly preserve security permissions when executing certain complex queries. This could result in the search disclosing the existence of documents the attacker should not be able to view. This could result in an attacker gaining additional insight into potentially sensitive indices.

CVSS3: 3.1
debian
почти 6 лет назад

Elasticsearch versions before 6.8.13 and 7.9.2 contain a document disc ...

CVSS3: 3.1
github
больше 5 лет назад

Privilege Context Switching Error in Elasticsearch

EPSS

Процентиль: 60%
0.01011
Низкий

3.5 Low

CVSS2

3.1 Low

CVSS3