← Back

CVE-2020-7020

nvd nist
Published: Oct 22, 2020Modified: Nov 21, 2024

JSON object

Loading...
3.1
Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
Exploitability: 1.6 / Impact: 1.4
Source: NVD

Description

Elasticsearch versions before 6.8.13 and 7.9.2 contain a document disclosure flaw when Document or Field Level Security is used. Search queries do not properly preserve security permissions when executing certain complex queries. This could result in the search disclosing the existence of documents the attacker should not be able to view. This could result in an attacker gaining additional insight into potentially sensitive indices.

Affected (2)

1 product
Elasticsearch
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Elastic
Before 6.8.13
From 7.0.0 to 7.9.2

References (6)

Source: security@elastic.co
Release NotesVendor Advisory
Source: security@elastic.co
Third Party Advisory
Source: security@elastic.co
Permissions RequiredVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Release NotesVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Permissions RequiredVendor Advisory

Timeline

No history available yet.