Elastic Enterprise Search before 7.9.0 contain a credential exposure flaw in the App Search interface. If a user is given the �developer� role, they will be able to view the administrator API credentials. These credentials could allow the developer user to conduct operations with the same permissions of the App Search administrator.
References
| Link | Resource |
|---|---|
| https://discuss.elastic.co/t/enterprise-search-7-9-0-security-update/245457 | Vendor Advisory |
Configurations
Information
Published : 2020-08-18 10:15
Updated : 2020-08-26 07:11
NVD link : CVE-2020-7018
Mitre link : CVE-2020-7018
JSON object : View
CWE
CWE-269
Improper Privilege Management
Products Affected
elastic
- enterprise_search


