Elastic Enterprise Search before 7.9.0 contain a credential exposure flaw in the App Search interface. If a user is given the �developer� role, they will be able to view the administrator API credentials. These credentials could allow the developer user to conduct operations with the same permissions of the App Search administrator.
References
Link | Resource |
---|---|
https://discuss.elastic.co/t/enterprise-search-7-9-0-security-update/245457 | Vendor Advisory |
Configurations
Information
Published : 2020-08-18 10:15
Updated : 2020-08-26 07:11
NVD link : CVE-2020-7018
Mitre link : CVE-2020-7018
JSON object : View
CWE
CWE-269
Improper Privilege Management
Products Affected
elastic
- enterprise_search